The verdict in three sentences
An unsigned webhook lets an attacker forge a "payment confirmed" notification and trigger a delivery without paying. The defense comes down to five controls: HMAC verification, idempotency, IP allowlist, replay protection and logging. In 2026, a 300-second tolerance window and a standard of 5 operator retry attempts are the markers to build in from day one.
The five hardening controls
Each control blocks a distinct class of attack. Stacking them gives defense in depth: even if one fails, the others hold.
| Control | Attack blocked | Implementation |
|---|---|---|
| HMAC verification | Forged notification | Compare header signature |
| Idempotency | Double processing | Unique key per event |
| IP allowlist | Unauthorized source | Filter operator IPs |
| Timestamp window | Delayed replay | Reject beyond 300 s |
| Logging | Blind investigation | Log every webhook |
HMAC verification runs on the raw body of the request, never on re-parsed JSON: re-parsing can reorder keys and break the signature.
2026 reference figures
Here are the 2026 reference values (estimates) to size your hardening.
| Parameter | 2026 value | Role |
|---|---|---|
| Timestamp tolerance window | 300 s | Anti-replay |
| Operator retry attempts | 5 | Guaranteed delivery |
| Delay between retries | Exponential (min → h) | Back-off |
| Expected response | Fast HTTP 200 | Else a new retry |
| Log retention | 90 days min | Investigation |
| Average incident cost | 200,000 to 2,000,000 FCFA | Fraud + reputation |
Return HTTP 200 immediately after persisting the event, then process asynchronously: if your slow processing exceeds the timeout, the operator retries and you risk double processing without idempotency.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Fatou runs a fashion marketplace in Dakar. An attacker notices her webhook endpoint doesn't verify the signature and posts 8 fake confirmations of 50,000 FCFA, triggering 400,000 FCFA of deliveries never paid for. After hardening — HMAC on the raw body, IP allowlist, 300-second window — these forged requests are rejected upstream. Cost of securing: one dev-day (~150,000 FCFA), against an avoided loss of 400,000 FCFA per incident.
FAQ
Why verify the HMAC signature? Without it, anyone who knows your URL can simulate a confirmed payment. The signature proves the notification truly comes from the operator.
What is the 300-second window? It's the maximum tolerance between the webhook's timestamp and receipt. Beyond it, you reject to block delayed replay attacks.
Why is idempotency critical? Operators retry an unacknowledged webhook up to 5 times. Without an idempotency key, you process the same payment several times.
Is the IP allowlist enough? No, alone it's fragile (spoofable IPs, changing ranges). It complements HMAC, it doesn't replace it.
How long should logs be kept? At least 90 days to investigate fraud or a dispute, ideally correlated with the operator's event_id.
Let's talk about your project. We audit and harden your mobile money webhooks against this production checklist. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
