# Verify webhooks

Run this integration code on the server unless the example explicitly mounts a browser button. `tokenVault`, `savePendingOAuthState`, `loadQentrahSession`, and event callbacks are application integration points, not exports supplied by the SDK. Implement them with your storage and user-session model.

## Webhook Verification

Use webhook helpers from server code. The signing secret must remain server-side.

```ts
// app/api/qentrah/webhooks/route.ts
import { createQentrahWebhookHandler } from "@qentrah/auth-sdk/partner/webhooks";

export const runtime = "nodejs";

export const POST = createQentrahWebhookHandler({
  signingSecret: process.env.QENTRAH_WEBHOOK_SIGNING_SECRET!,
  handlers: {
    async "client.created"(event) {
      await syncClientCreated(event.data);
    },
    async "client.updated"(event) {
      await syncClientUpdated(event.data);
    },
    async "client.deleted"(event) {
      await syncClientDeleted(event.data);
    },
  },
  async onUnhandledEvent(event) {
    await recordUnhandledEvent(event.type);
  },
});
```

Verify against the original request body before parsing JSON. The helper does that for standard `Request` objects.