beyondcode / beyondcode/laravel-mailbox

Mailgun - HTTP webhook signing key instead of API key

Open
#119 6 comments 13 reactions 0 assignees View on GitHub
Dominant language
PHP
Stars
1.1k
Forks
127
PR merge metrics
No merged PRs in 30d

Description

Hello!

We had some issues today with the 'verifySignature' function in the 'MailgunRequest' class. We tried to use an account wide API key and a domain specific API key on Mailgun. We couldn't verify the signature with those keys. You must use the 'HTTP webhook signing key' from Mailgun to let the 'verifySignature' function succeed.

**The Laravel Mailbox -> Drivers -> Available drivers -> Mailgun documentation says the following**
To use Laravel Mailbox with your Mailgun account, you first need to set the MAILBOX_MAILGUN_KEY environment variable to your ~~**Mailgun API key**~~.

**But it should be**
To use Laravel Mailbox with your Mailgun account, you first need to set the MAILBOX_MAILGUN_KEY environment variable to your **HTTP webhook signing key**.

The HTTP webhook signing key can be found here when logged in on Mailgun: Click on your name (upper right corner) -> API Security.

Just an heads up for someone that faces this problem as well.
And perhaps the documentation could be updated.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.