# Verify a Webhook HMAC Signature
Stripe/GitHub-style webhooks sign the raw request body with HMAC-SHA256 so
receivers can reject forged deliveries before doing any work.
### Task
Implement `verify_signature(payload: bytes, signature: str, secret: str) -> bool`
that returns `True` only when `signature == "sha256=" + hmac_hex(payload, secret)`.
Use `hmac.compare_digest` (never `==`) so attackers cannot time the comparison.
### Example
`verify_signature(b'{"id": 1}', "sha256=" + hmac.new(b"s", b'{"id": 1}',
hashlib.sha256).hexdigest(), "s")` → `True`; any tampered byte → `False`.