Security operations track · 3 min
Verify a signed webhook
Recompute the HMAC yourself and see why a changed body fails.
The idea
1Events travel as signed webhooks
AuthMantra can stream audit events to your SIEM by signed webhook, or to Splunk HTTP Event Collector.
2The header carries a time and a signature
X-AuthMantra-Signature reads t=<unix>,v1=<signature>. The signature is an HMAC-SHA-256 of the text t, a dot, then the raw body.
3Recompute and compare
Use your shared secret. If your result equals v1, the body is untouched and came from someone holding the secret.
4Check the age too
Reject old timestamps, so a captured request cannot be replayed later.
Try it
Verify it yourself
Sample secret and event only. Edit the body, then verify.
This exercise needs JavaScript. Here is the answer key.
Signed text: t, a dot, then the body. Secret in this sample: demo_secret_not_real.
Check yourself
1 of 3 What is signed?
2 of 3 Why compare the timestamp?
3 of 3 You changed one character in the body. The check
Answer key
- What is signed? t, a dot, then the raw body. Both the time and the body are covered.
- Why compare the timestamp? To reject replays. An old captured request fails the age check.
- You changed one character in the body. The check Fails. The HMAC no longer matches.