For security reasons, when sending and receiving data and information to and from an external endpoint (i.e. real-time webhooks, external resources) we recommend verifying the callback authenticity by signing the payload with the shared secret (SHA256 HMAC) and comparing the result with the X-CommerceLayer-Signature callback header. In details:
Read the X-CommerceLayer-Signature header and get the encrypted signature.
Rebuild the signature according to the SHA256 HMAC algorithm, using the payload body and the provided shared secret.
Compare your signature with the one you got from the header.
If the two signatures match, you can proceed safely — if not, you can't trust the callback.
This is a sample script in Node.js that you can use as a reference to check the signature: