Skydio will send a “Skydio-Verification” header as part of every webhook request. This header contains a JWT (JSON Web Token) as its value with a payload that allows you to verify the request hasn’t been tampered with.
Step 1: Read the headers from the JWT
Using your preferred JWT package, you can directly read headers from the JWT sent with the request. The headers should include the following:
{
"alg": "HS256",
"kid": "df99b373-e751-44a6-a530-90bf435d4590",
"typ": "JWT"
}Step 2: Issue a request to Skydio’s /webhook_validation endpoint
/webhook_validation endpointIssue an HTTP GET request to https://api.skydio.com/api/webhook_validation?key_id=<KEY_ID>, where KEY_ID refers to the kid value stored in the JWT header.
NOTE: This endpoint requires a valid API token - you can generate one inSkydio Cloud.
A valid response should include the following fields:
{
"kty": "oct",
"kid": "df99b373-e751-44a6-a530-90bf435d4590",
"k": <PRIVATE_KEY>,
"alg": "HS256"
}If this request results in an error, reject the request.
Step 3: Use the key to extract JWT payload
Using your preferred JWT package, use the value stored in k above to verify the JWT. The JWT payload should have the following structure:
{
"request_json_body": <SHA256>
}Step 4: Validate the payload
Take the SHA256 of the webhook request’s body and compare that to the SHA256 string stored in the JWT payload.
If these two strings do not match, reject the request.
