Category

How to Secure Webhooks in BoldDesk

Updated:

Webhook endpoints are publicly accessible and may receive requests from unauthorized sources. Securing the endpoint helps protect sensitive webhook data, verify that requests originate from BoldDesk, and detect payload tampering.

This article explains how to secure BoldDesk webhooks using HTTPS endpoints, password or API key authentication, HMAC-SHA256 webhook signing, and BoldDesk outbound IP address validation.

Webhook endpoints

The webhook request is the same as any other HTTP request, which is a plain-text protocol. So, the data is in readable format during the webhook request. Attackers can easily intercept these messages and steal sensitive data such as user information.

You can secure webhook data by using an HTTPS URL which ensures that all data sent is encrypted and unreadable.

It supports only HTTPS URLs where data will be sent when a webhook is triggered.

A webhook will not be triggered in local environments such as localhost.

Webhook authentication

You should enable authentication when creating a webhook to send the webhook data securely and verify whether it is sent from BoldDesk or not. Even though it is optional, you are strongly advised to enable the authentication.

The following are the two methods for authenticating the webhook URL.

  • Password
    When creating a webhook, you can use password authentication (Basic Auth) to provide the username and password. The credentials (Username:Password) will be Base64 encoded and sent in the Authorization header (Authorization: Basic <Credential>).

  • API Key
    When creating a webhook, users can use API authentication (Basic Auth) to provide the API Key. The API key will be Base64 encoded and sent in the Authorization header (Authorization: Basic <API Key>).

Webhook Signing

Webhook Signing webhook, you can use request signature authentication to provide the secret key. This secret key is used to sign the payload (HMAC-SHA256), generate a Base64 encoded signature, and send it in the header (x-signature). This can be used to validate the payload’s integrity at the receiver end (X-Signature: <Signature>).

Please make sure to whitelist or validate that the incoming webhook requests originate from the following BoldDesk outbound IP addresses:
34.48.64.2
34.145.236.120

Frequently Asked Questions

  1. Why should I secure a webhook endpoint?

    A webhook URL is publicly accessible, so an unauthorized sender could attempt to submit or modify webhook data. Securing the endpoint helps verify that requests originate from BoldDesk and protects sensitive information transmitted in the webhook payload.

  2. Does BoldDesk support HTTP webhook URLs?

    No. BoldDesk supports only HTTPS webhook URLs. HTTPS encrypts the transmitted data and prevents the webhook payload from being sent as readable plain text.

  3. Can a BoldDesk webhook be triggered on localhost?

    No. BoldDesk webhooks cannot be triggered in local environments such as localhost. Configure a publicly accessible HTTPS endpoint to receive webhook requests.

  4. Which authentication methods are available for BoldDesk webhooks?

    BoldDesk supports password authentication and API key authentication.

    • Password authentication: The username and password are Base64 encoded and sent in the Authorization header.
    • API key authentication: The API key is Base64 encoded and sent in the Authorization header.
  5. How can I verify the integrity and origin of a webhook request?

    Enable webhook signing and configure a secret key. BoldDesk uses the secret key to sign the webhook payload using HMAC-SHA256. The generated signature is Base64 encoded and sent in the x-signature header.

    Validate the signature at the receiving endpoint and allow requests from the following BoldDesk outbound IP addresses:

    • 34.48.64.2
    • 34.145.236.120

Related Articles

  1. BoldDesk API Authentication
  2. IP Allowlisting for BoldDesk Application
Was this article useful?
Like
Dislike
Help us improve this page
Please provide feedback or comments
Comments (0)
Access denied
Access denied
Access denied
Access denied

No articles or sections found
No articles or sections found