Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial

Security operations track · 3 min

Verify a signed webhook

Recompute the HMAC yourself and see why a changed body fails.

The idea

  1. 1Events travel as signed webhooks

    AuthMantra can stream audit events to your SIEM by signed webhook, or to Splunk HTTP Event Collector.

  2. 2The header carries a time and a signature

    X-AuthMantra-Signature reads t=<unix>,v1=<signature>. The signature is an HMAC-SHA-256 of the text t, a dot, then the raw body.

  3. 3Recompute and compare

    Use your shared secret. If your result equals v1, the body is untouched and came from someone holding the secret.

  4. 4Check the age too

    Reject old timestamps, so a captured request cannot be replayed later.

Try it

Verify it yourself

Sample secret and event only. Edit the body, then verify.

This exercise needs JavaScript. Here is the answer key.

Signed text: t, a dot, then the body. Secret in this sample: demo_secret_not_real.

Check yourself

1 of 3 What is signed?

2 of 3 Why compare the timestamp?

3 of 3 You changed one character in the body. The check

Answer key
  1. What is signed? t, a dot, then the raw body. Both the time and the body are covered.
  2. Why compare the timestamp? To reject replays. An old captured request fails the age check.
  3. You changed one character in the body. The check Fails. The HMAC no longer matches.