Validate Customer Data
Ensure data quality with regex patterns or custom validation endpoints.
Validation helps ensure customers enter correct information, reducing fulfillment errors and support requests. Fungies supports two validation methods: regex patterns and custom validation URLs.
Regex Validation
Use regular expressions to validate text field input directly in the browser. Invalid input is rejected before the customer can submit.
How to Add Regex Validation
- Edit your custom field in the Dashboard
- Enter a regex pattern in the Regex field
- Save your changes
Regex validation happens client-side, providing instant feedback to customers.
Common Patterns
| Use Case | Pattern | Matches |
|---|---|---|
| Numbers only | ^[0-9]+$ | 12345 |
| Letters only | ^[a-zA-Z]+$ | PlayerOne |
| Alphanumeric | ^[a-zA-Z0-9]+$ | Player123 |
| Username (3-20 chars) | ^[a-zA-Z0-9_]{3,20}$ | cool_player_99 |
^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}$ | user@example.com | |
| UUID | ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$ | 550e8400-e29b-... |
| Date (YYYY-MM-DD) | ^\d{4}-\d{2}-\d{2}$ | 2024-01-15 |
Regex Tips
// Start (^) and end ($) anchors ensure the entire input matches
^[a-zA-Z0-9]+$ // ✓ Matches: "abc123"
// ✗ Rejects: "abc 123" (space not allowed)
// Character classes define allowed characters
[a-zA-Z] // Any letter
[0-9] or \d // Any digit
[a-zA-Z0-9_] // Letters, digits, or underscore
// Quantifiers specify length
{3,20} // Between 3 and 20 characters
+ // One or more
* // Zero or moreTest your regex patterns at regex101.com before adding them to Fungies.
Custom Validation URL
For complex validation that can't be expressed as regex—like checking if a player ID exists in your database—use a custom validation endpoint.
How It Works
- Customer enters a value
- Fungies sends a POST request to your validation URL
- Your API checks if the value is valid
- Return
200 OKfor valid, any other status for invalid
Request Format
Fungies sends a POST request with the field value and a context object:
{
"playerId": "Player_12345",
"context": {
"user": {
"object": "user",
"id": "123e4567-e89b-12d3-a456-426614174000",
"email": "customer@example.com"
},
"item": {
"name": "Pro Plan - Monthly",
"quantity": 1,
"currency": "USD"
}
}
}The first key is your custom field's Key, and its value is what the customer entered. context
carries the buyer and the item being purchased, so you can validate against both — context.user is
null for a guest checkout. Read the field by its own Key rather than taking the first key in the
body; do not rely on key order.
Response
| Status | Meaning |
|---|---|
2xx | Valid - customer can proceed |
| Anything else | Invalid - customer sees an error |
A request that times out, or fails to connect at all, counts as invalid — the customer is
blocked from checking out. Keep the endpoint fast and available, and return 2xx for anything you
cannot decide on.
Example Endpoint
// Express.js example
app.post('/validate/player-id', async (req, res) => {
const { playerId } = req.body;
// Check if player exists in your database
const player = await db.players.findById(playerId);
if (player) {
return res.status(200).json({ valid: true });
}
return res.status(400).json({
valid: false,
message: 'Player not found'
});
});Securing Your Validation Endpoint
Without signature verification, anyone could call your validation endpoint. Always verify the signature in production.
Validation requests are only signed once you set a validation URL secret on the field. With no
secret configured, the request arrives with no x-fngs-signature header at all — so an endpoint
that rejects unsigned requests will fail every validation, and one that skips the check when the
header is absent is not protected. Set the secret in the Dashboard first, then enforce the
signature.
Once a secret is set, Fungies signs validation requests the same way as webhooks. The signature is in the x-fngs-signature header:
x-fngs-signature: sha256_6808ed5be1262b60818359fa586145810d0793e8a677f1326520d3844e21b640Verify the Signature
Use your validation URL secret (set in the Dashboard) to verify requests:
import crypto from 'crypto';
function verifySignature(payload, signature, secret) {
const expectedSignature = 'sha256_' + crypto
.createHmac('sha256', secret)
.update(payload)
.digest('hex');
return crypto.timingSafeEqual(
Buffer.from(signature),
Buffer.from(expectedSignature)
);
}
app.post('/validate/player-id', (req, res) => {
const signature = req.headers['x-fngs-signature'];
const rawBody = req.rawBody; // Must be raw, unparsed body
if (!verifySignature(rawBody, signature, process.env.VALIDATION_SECRET)) {
return res.status(401).json({ error: 'Invalid signature' });
}
// ... validation logic
});See the webhook signature verification guide for more details.
Combining Validation Methods
You can use both regex and URL validation on the same field:
- Regex runs first - Catches format errors instantly (client-side)
- URL validation runs second - Checks business logic (server-side)
This gives customers fast feedback on format errors while still validating against your backend.
Next Steps
Last updated