XFlux
Python tutorial

Twitter webhook Python handler (signed monitor.hit POSTs)

Receive account-monitor alerts in Flask, FastAPI, or any WSGI/ASGI app. Verify X-XFlux-Signature over the raw body, then route to Discord, Slack, or your trading logic.

Raw body for HMAC

Sign over `{timestamp}.{raw_body}`. Read request bytes before JSON parse — re-serializing breaks verification.

compare_digest

Use hmac.compare_digest for timing-safe signature checks.

Pair with the read API

Same key for /api/v1/search and timelines — Python guide: /docs/guides/python.

Python setup

  1. 1

    Expose HTTPS and create a monitor webhook

    ngrok for local tests. Copy the signing secret from Dashboard → Monitors.

  2. 2

    Verify headers then parse JSON

    Check X-XFlux-Timestamp skew (~5 minutes) and X-XFlux-Signature before trusting the body.

  3. 3

    Handle monitor.test and monitor.hit

    Test events validate wiring on Free; live hits need Starter+. Node users: /twitter-webhook-nodejs.

Flask verification sketch

Load the secret from env. Prefer a production ASGI stack when you scale.

import hmac, hashlib, os, time
from flask import Flask, request, abort

app = Flask(__name__)
SECRET = os.environ["XFLUX_WEBHOOK_SECRET"].encode()

@app.post("/webhooks/xflux")
def xflux_webhook():
    ts = request.headers.get("X-XFlux-Timestamp", "")
    sig = request.headers.get("X-XFlux-Signature", "")
    raw = request.get_data()  # bytes
    if abs(time.time() - int(ts or "0")) > 300:
        abort(401)
    expected = "sha256=" + hmac.new(
        SECRET, f"{ts}.".encode() + raw, hashlib.sha256
    ).hexdigest()
    if not hmac.compare_digest(expected, sig):
        abort(401)
    event = request.get_json(force=True)
    if event.get("event") == "monitor.hit":
        print(event["tweet"]["authorUsername"], event["tweet"]["text"])
    return "ok", 200

FAQ

Is this official Twitter API v2?
No. XFlux is an independent read API + monitors. Python examples for REST reads are at /docs/guides/python; this page is webhook verification.
Discord without Python?
Paste a Discord Incoming Webhook into the monitor — see /twitter-discord-alerts.
Full header reference?
See /docs/webhooks and the hub at /twitter-webhook.

Related guides

Try account monitors free

Free includes 1 monitor and Dashboard hit history. Live webhook delivery starts on Starter ($19/mo).

Twitter Webhook in Python — Verify XFlux Signatures | XFlux