Signature Verification
A200 from key/check is only half the check. The response carries an HMAC you must verify with the same auth secret you signed the request with. Skip this and anyone who can intercept traffic — or hook the executor’s HTTP function — can feed your script a fake valid.
Both signatures
Both are lowercase-hex HMAC-SHA1 keyed with the auth secret (40 hex chars).
expiresAtUnix is the key’s expiry as Unix seconds — 0 when expires_at is null (never-expires key). project_id is the internal UUID from the response, not the public ID you sent.
Verification steps
- Require
nonce_echo == nonceyou sent. Mismatch → reject. - Compute
expected = HMAC_SHA1(auth_secret, nonce_echo .. "|" .. status .. "|" .. expiresAtUnix .. "|" .. project_id). - Compare with
signaturefrom the response. Mismatch → reject. - Only then treat the key as valid.
Example
Verified round-trip using a real key and secret shape:What this buys you
- Fake responses die. An attacker without the auth secret cannot produce a valid
signaturefor a forgedvalidbody. - Replays die. Each call uses a fresh nonce; a captured response verifies only against its own nonce.
- Edits die. Bumping
expires_ator swappingstatusinvalidates the signature.