Skip to main content
@proofage/node signs every request, verifies webhooks with a drop-in handler for any framework with a standard Request, and ships a setup check.

Install

Requires Node.js 22 or newer.

Configure

Check the setup from a terminal; it reads .env.local and .env:

Create a verification

Request bodies use the API’s snake_case keys.

Read results

Receive webhooks

The handler answers 200 when your callback succeeds, 401 on a bad signature, 400 on invalid JSON and 500 if your callback throws. The timestamp tolerance is 300 seconds (PROOFAGE_WEBHOOK_TOLERANCE). For other frameworks, handleWebhook(request) returns { verified, payload, error }, and verifyWebhookSignature({ rawBody, signature, timestamp, authClient }) throws on a bad request.

Everything else

The server-side capture flow (consent, upload, submit) is in the package README and on Capture in your own UI.

Errors and retries

GET requests retry on 408, 429, 5xx, timeouts and network errors. POST requests retry only on 429 and on a connection that never opened, never on a 5xx or a timeout, so a retry cannot create a second verification. A 429 waits for Retry-After.