My webhook is returning 401
Common causes and the fixes that resolve them.
Where is the 401 coming from — Getme or my server?
Getme never sends 401 to you. A 401 in Getme’s webhook log means your server returned 401 when Getme delivered the event. The fix is on your side.
Most likely cause?
Your endpoint is rejecting the signature. Getme signs every webhook with the secret you set in Developers → Webhooks. If your verification logic uses a different secret (or none), you return 401 and Getme retries.
How do I verify the signature?
Read the Getme-Signature header, split on commas to get the timestamp and signature, then HMAC-SHA-256 the payload with your webhook secret. If the computed signature matches, accept the request. The Developers docs include a 5-line example for Node and Python.
What if I rotated the secret?
Rotation invalidates the old secret immediately. Update your env var on every server (including stand-bys) and redeploy. Getme keeps the old secret valid for a 60-second grace window so deploys do not drop events.
Will Getme stop retrying eventually?
Yes. Getme retries with exponential back-off for 24 hours, then stops. The event is then visible in Developers → Webhooks → Failures so you can replay it after fixing the endpoint.