Verify webhooks
Run this integration code on the server unless the example explicitly mounts a browser button. tokenVault, savePendingOAuthState, loadQentrahSession, and event callbacks are application integration points, not exports supplied by the SDK. Implement them with your storage and user-session model.
Webhook Verification
Use webhook helpers from server code. The signing secret must remain server-side.
// app/api/qentrah/webhooks/route.ts
import { createQentrahWebhookHandler } from "@qentrah/auth-sdk/partner/webhooks";
export const runtime = "nodejs";
export const POST = createQentrahWebhookHandler({
signingSecret: process.env.QENTRAH_WEBHOOK_SIGNING_SECRET!,
handlers: {
async "client.created"(event) {
await syncClientCreated(event.data);
},
async "client.updated"(event) {
await syncClientUpdated(event.data);
},
async "client.deleted"(event) {
await syncClientDeleted(event.data);
},
},
async onUnhandledEvent(event) {
await recordUnhandledEvent(event.type);
},
});Verify against the original request body before parsing JSON. The helper does that for standard Request objects.
Source captured: 2026-10-11