# Verification of bot\_message\_notification

**URL:** <https://community.sendbird.com/t/verification-of-bot-message-notification/9788>\
**Category:** Miscellaneous\
**Tags:** chatbot\
**Created:** [July 18, 2024, 3:41pm UTC](https://community.sendbird.com/t/verification-of-bot-message-notification/9788 "2024-07-18T15:41:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guy\_Guy](https://avatars.discourse-cdn.com/v4/letter/g/94ad74/32.png) [@Guy\_Guy](https://community.sendbird.com/u/Guy_Guy)\
**Post date:** [July 18, 2024, 3:41pm UTC](https://community.sendbird.com/t/verification-of-bot-message-notification/9788/1 "2024-07-18T15:41:16Z")

</div>

**[Question]**  
The docs for chat bot say

> An opaque string that identifies the bot. This token should be added to all requests sent to `bot_callback_url` to verify that they come from Sendbird server.

Yet, I do see a `x-sendbird-signature` header on the callback.

Is using `x-sendbird-signature` possible for this? I guess `bot.bot_token` is the secret to be used to sign?

---

<div class="post-metadata">

**Author:** ![Doug\_Exner](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/doug_exner/32/52_2.png) [@Doug\_Exner](https://community.sendbird.com/u/Doug_Exner)\
**Post date:** [July 18, 2024, 4:52pm UTC](https://community.sendbird.com/t/verification-of-bot-message-notification/9788/2 "2024-07-18T16:52:32Z")

</div>

The x-sendbird-signature works the same way as with regular chat webhook. It still uses the API Token.
