# Label Webhook Authentication

**URL:** <https://community.shiphero.com/t/label-webhook-authentication/543>\
**Category:** GraphQL API\
**Created:** [June 19, 2020, 5:28am UTC](https://community.shiphero.com/t/label-webhook-authentication/543 "2020-06-19T05:28:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![adamc](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@adamc](https://community.shiphero.com/u/adamc)\
**Post date:** [June 19, 2020, 5:28am UTC](https://community.shiphero.com/t/label-webhook-authentication/543/1 "2020-06-19T05:28:41Z")

</div>

Hi  
I am a carrier looking at developing your Carrier Label Webhook. I have had your support team configure the webhook for us, but when receiving the webhook, we cannot see the API token in either the headers or body. Where can we expect to receive the token to authenticate the the request and customer sending it?

We plan on implementing this webhook to multiple mutual customers.

Regards,  
Adam

---

<div class="post-metadata">

**Author:** ![tomasw](https://sea2.discourse-cdn.com/flex020/user_avatar/community.shiphero.com/tomasw/32/248_2.png) [@tomasw](https://community.shiphero.com/u/tomasw)\
**Post date:** [June 19, 2020, 1:58pm UTC](https://community.shiphero.com/t/label-webhook-authentication/543/2 "2020-06-19T13:58:10Z")

</div>

Hi @adamc  
We currently don’t have that available for that Webhook.  
Do you want me to log a feature request for this to be added?  
Would something like [Request Verification](https://shipheropublic.docs.apiary.io/#reference/webhooks/request-verification) work for you?  
Thanks in advance!  
Tom

---

<div class="post-metadata">

**Author:** ![adamc](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@adamc](https://community.shiphero.com/u/adamc)\
**Post date:** [June 21, 2020, 10:39pm UTC](https://community.shiphero.com/t/label-webhook-authentication/543/3 "2020-06-21T22:39:24Z")

</div>

Hi @tomasw

Will the Request Verification link back to the API Secret that is setup in [https://app.shiphero.com/dashboard/settings/api](https://app.shiphero.com/dashboard/settings/api) when we setup the API Credentials?

Adam

---

<div class="post-metadata">

**Author:** ![tomasw](https://sea2.discourse-cdn.com/flex020/user_avatar/community.shiphero.com/tomasw/32/248_2.png) [@tomasw](https://community.shiphero.com/u/tomasw)\
**Post date:** [June 22, 2020, 12:52pm UTC](https://community.shiphero.com/t/label-webhook-authentication/543/4 "2020-06-22T12:52:24Z")

</div>

Hi @adamc  
Yes, with the other Webhooks that is how it works, with the API Secret and the Body of the request you can encode it and match it to the hmac  
Would this work for you?  
Thanks again!  
Tom

---

<div class="post-metadata">

**Author:** ![adamc](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@adamc](https://community.shiphero.com/u/adamc)\
**Post date:** [June 23, 2020, 3:44am UTC](https://community.shiphero.com/t/label-webhook-authentication/543/5 "2020-06-23T03:44:21Z")

</div>

Hi @tomasw  
Yes this would work. Having a look at your documents and test webhook we have received there is no header details for hmac values. Does this need to be turned on additionally to the webhook?

We must have some way to identify the receiving webhook otherwise we will not be able to use your generate label webhook.

Adam

---

<div class="post-metadata">

**Author:** ![tomasw](https://sea2.discourse-cdn.com/flex020/user_avatar/community.shiphero.com/tomasw/32/248_2.png) [@tomasw](https://community.shiphero.com/u/tomasw)\
**Post date:** [June 23, 2020, 8:14pm UTC](https://community.shiphero.com/t/label-webhook-authentication/543/6 "2020-06-23T20:14:36Z")

</div>

Hi @adamc  
I just wanted to let you know I submitted a feature request for this to be added.  
Currently the Generate Label Webhook doesn’t have this verification I mentioned.  
I will let you know as soon as I have an update about this.  
Thank you again for your patience  
Tom

---

<div class="post-metadata">

**Author:** ![adamc](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@adamc](https://community.shiphero.com/u/adamc)\
**Post date:** [June 23, 2020, 10:50pm UTC](https://community.shiphero.com/t/label-webhook-authentication/543/7 "2020-06-23T22:50:58Z")

</div>

Thanks @tomasw. We really appreciate it. 🙂

---

<div class="post-metadata">

**Author:** ![tomasw](https://sea2.discourse-cdn.com/flex020/user_avatar/community.shiphero.com/tomasw/32/248_2.png) [@tomasw](https://community.shiphero.com/u/tomasw)\
**Post date:** [November 5, 2020, 7:33pm UTC](https://community.shiphero.com/t/label-webhook-authentication/543/8 "2020-11-05T19:33:29Z")

</div>

Hi @adamc!  
You should be receiving the `x-shiphero-hmac-sha256` now on your Generate Label Webhook URL.  
Thank you very much while we worked on this.  
Please let me know if there is anything else I could help with!  
Tom
