I spent an evening convinced GitHub was sending broken webhook signatures. It wasn't. echo was.

The setup

Chngd's GitHub Marketplace webhook verifies every inbound event with HMAC-SHA256, comparing GitHub's X-Hub-Signature-256 header against a signature computed from the raw request body and a shared secret.

Every single request failed verification. Not intermittently. Every one, from the very first test delivery.

Where I looked first