Skip to main content

Signature Verification

A 200 from key/check is only half the check. The response carries an HMAC you must verify with the same auth secret you signed the request with. Skip this and anyone who can intercept traffic — or hook the executor’s HTTP function — can feed your script a fake valid.

Both signatures

Both are lowercase-hex HMAC-SHA1 keyed with the auth secret (40 hex chars). expiresAtUnix is the key’s expiry as Unix seconds — 0 when expires_at is null (never-expires key). project_id is the internal UUID from the response, not the public ID you sent.

Verification steps

  1. Require nonce_echo == nonce you sent. Mismatch → reject.
  2. Compute expected = HMAC_SHA1(auth_secret, nonce_echo .. "|" .. status .. "|" .. expiresAtUnix .. "|" .. project_id).
  3. Compare with signature from the response. Mismatch → reject.
  4. Only then treat the key as valid.
Step 1 matters even though the signature covers the nonce: it’s what stops replaying an old signed response at your script.

Example

Verified round-trip using a real key and secret shape:
The reference client does all of this for you and fails closed — embed it instead of hand-rolling unless you have a reason not to.

What this buys you

  • Fake responses die. An attacker without the auth secret cannot produce a valid signature for a forged valid body.
  • Replays die. Each call uses a fresh nonce; a captured response verifies only against its own nonce.
  • Edits die. Bumping expires_at or swapping status invalidates the signature.
It does not stop someone deleting the check from your script — that’s obfuscation’s job.