# Change requests in your own tools

> Every request for changes arrives signed on your route, with the client’s comment, ready to become a ticket. How to do it with colis, what to watch, and where it is written down.

Canonical: https://colis-site.vercel.app/en/use-cases/corrections-dans-vos-outils · Markdown: https://colis-site.vercel.app/en/use-cases/corrections-dans-vos-outils.md · Français: https://colis-site.vercel.app/use-cases/corrections-dans-vos-outils

Every request for changes arrives signed on your route, with the client’s comment, ready to become a ticket.

```ts
import { verifyWebhook } from '@colis/protocol'

export async function POST(request: Request) {
  const body = await request.text()
  const result = await verifyWebhook(process.env.DROP_WEBHOOK_SECRET!, request.headers, body)
  if (!result.valid) return new Response(null, { status: 401 })

  const event = JSON.parse(body)
  if (event.type === 'parcel.changes_requested') {
    await createIssue({                       // your tracker
      title: `Corrections : ${event.data.filename}`,
      body: event.data.comment,
      reference: event.data.code,
    })
  }

  return new Response(null, { status: 204 })
}
```

## What is actually going on.
### The problem
Client feedback gets lost between email, chat and calls. The one that matters, “the logo as SVG, and a lighter background”, has to end up in your tracker.

### What colis does about it
Point `DROP_WEBHOOK_URL` at a route of yours. `verifyWebhook` from `@colis/protocol` checks the Standard Webhooks signature (HMAC-SHA256) with the same code the deployment signs with. On `parcel.changes_requested`, `data.comment` carries what the client wrote: open the ticket, and link the parcel by its code.

## The things that are easy to get wrong.
- **Read the raw body** — The signature covers the bytes received: `request.text()` before any `JSON.parse`.
- **Five minutes of tolerance** — A timestamp more than five minutes off is refused, so an old delivery cannot be replayed.
- **No secret in the event** — `data` never holds the password, its hash, or the sender’s token.

Packages: @colis/protocol. [Webhooks, in the README](https://github.com/mamadouwhile/colis/blob/main/templates/drop/README.md#webhooks)
