Twitter webhook Python handler (signed monitor.hit POSTs)
Receive account-monitor alerts in Flask, FastAPI, or any WSGI/ASGI app. Verify X-XFlux-Signature over the raw body, then route to Discord, Slack, or your trading logic.
Raw body for HMAC
Sign over `{timestamp}.{raw_body}`. Read request bytes before JSON parse — re-serializing breaks verification.
compare_digest
Use hmac.compare_digest for timing-safe signature checks.
Pair with the read API
Same key for /api/v1/search and timelines — Python guide: /docs/guides/python.
Python setup
- 1
Expose HTTPS and create a monitor webhook
ngrok for local tests. Copy the signing secret from Dashboard → Monitors.
- 2
Verify headers then parse JSON
Check X-XFlux-Timestamp skew (~5 minutes) and X-XFlux-Signature before trusting the body.
- 3
Handle monitor.test and monitor.hit
Test events validate wiring on Free; live hits need Starter+. Node users: /twitter-webhook-nodejs.
Flask verification sketch
Load the secret from env. Prefer a production ASGI stack when you scale.
import hmac, hashlib, os, time
from flask import Flask, request, abort
app = Flask(__name__)
SECRET = os.environ["XFLUX_WEBHOOK_SECRET"].encode()
@app.post("/webhooks/xflux")
def xflux_webhook():
ts = request.headers.get("X-XFlux-Timestamp", "")
sig = request.headers.get("X-XFlux-Signature", "")
raw = request.get_data() # bytes
if abs(time.time() - int(ts or "0")) > 300:
abort(401)
expected = "sha256=" + hmac.new(
SECRET, f"{ts}.".encode() + raw, hashlib.sha256
).hexdigest()
if not hmac.compare_digest(expected, sig):
abort(401)
event = request.get_json(force=True)
if event.get("event") == "monitor.hit":
print(event["tweet"]["authorUsername"], event["tweet"]["text"])
return "ok", 200FAQ
- Is this official Twitter API v2?
- No. XFlux is an independent read API + monitors. Python examples for REST reads are at /docs/guides/python; this page is webhook verification.
- Discord without Python?
- Paste a Discord Incoming Webhook into the monitor — see /twitter-discord-alerts.
- Full header reference?
- See /docs/webhooks and the hub at /twitter-webhook.
Related guides
Try account monitors free
Free includes 1 monitor and Dashboard hit history. Live webhook delivery starts on Starter ($19/mo).