Digital Africa11 min read

Securing mobile money webhooks: signatures and anti-fraud (2026)

Mohamed Bah·Fondateur, Kolonell
August 13, 2026
Share:
Securing mobile money webhooks: signatures and anti-fraud (2026)

Securing mobile money webhooks: signatures and anti-fraud (2026)

Digital Africa

The verdict in three sentences

An unsigned webhook lets an attacker forge a "payment confirmed" notification and trigger a delivery without paying. The defense comes down to five controls: HMAC verification, idempotency, IP allowlist, replay protection and logging. In 2026, a 300-second tolerance window and a standard of 5 operator retry attempts are the markers to build in from day one.

The five hardening controls

Each control blocks a distinct class of attack. Stacking them gives defense in depth: even if one fails, the others hold.

ControlAttack blockedImplementation
HMAC verificationForged notificationCompare header signature
IdempotencyDouble processingUnique key per event
IP allowlistUnauthorized sourceFilter operator IPs
Timestamp windowDelayed replayReject beyond 300 s
LoggingBlind investigationLog every webhook

HMAC verification runs on the raw body of the request, never on re-parsed JSON: re-parsing can reorder keys and break the signature.

2026 reference figures

Here are the 2026 reference values (estimates) to size your hardening.

Parameter2026 valueRole
Timestamp tolerance window300 sAnti-replay
Operator retry attempts5Guaranteed delivery
Delay between retriesExponential (min → h)Back-off
Expected responseFast HTTP 200Else a new retry
Log retention90 days minInvestigation
Average incident cost200,000 to 2,000,000 FCFAFraud + reputation

Return HTTP 200 immediately after persisting the event, then process asynchronously: if your slow processing exceeds the timeout, the operator retries and you risk double processing without idempotency.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Mini case study

Fatou runs a fashion marketplace in Dakar. An attacker notices her webhook endpoint doesn't verify the signature and posts 8 fake confirmations of 50,000 FCFA, triggering 400,000 FCFA of deliveries never paid for. After hardening — HMAC on the raw body, IP allowlist, 300-second window — these forged requests are rejected upstream. Cost of securing: one dev-day (~150,000 FCFA), against an avoided loss of 400,000 FCFA per incident.

FAQ

Why verify the HMAC signature? Without it, anyone who knows your URL can simulate a confirmed payment. The signature proves the notification truly comes from the operator.

What is the 300-second window? It's the maximum tolerance between the webhook's timestamp and receipt. Beyond it, you reject to block delayed replay attacks.

Why is idempotency critical? Operators retry an unacknowledged webhook up to 5 times. Without an idempotency key, you process the same payment several times.

Is the IP allowlist enough? No, alone it's fragile (spoofable IPs, changing ranges). It complements HMAC, it doesn't replace it.

How long should logs be kept? At least 90 days to investigate fraud or a dispute, ideally correlated with the operator's event_id.

Let's talk about your project. We audit and harden your mobile money webhooks against this production checklist. WhatsApp +221 77 596 93 33.

Tags:#webhook#securite#signature hmac#mobile money#anti-fraude#idempotence#paiement#afrique-digitale
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.