Skip to content
Ask a question in your own words

A trigger webhook is rejected with 401

A 401 means Mando could not verify your request signature. Check the trigger URL, both signing headers, a fresh unix-seconds timestamp, and the current secret.

Written by: Malaz Madani43 minutes ago2 min read

A 401 unauthorized from a trigger webhook means Mando could not verify your request. Every signing problem returns the same 401 on purpose, so the endpoint cannot be used to probe which triggers exist.

Check the URL and headers

  • Wrong trigger URL: copy the exact Webhook URL from the Connection card; a mistyped or stale trigger id lands here.
  • Missing headers: send both X-Mando-Timestamp and X-Mando-Signature on every request.

Check the timestamp and signature

  • Bad timestamp: send the current unix time in whole seconds, not milliseconds. A request more than five minutes old is rejected, so re-sign per request and fix any clock drift.
  • Bad signature: use the current secret (the old one stops working the moment you rotate), sign the raw body, and use the exact recipe from the How to sign panel.

When it is not a 401

Other rejections are not signing problems: a 400 means your JSON body is malformed; a 403 means trigger webhooks are not enabled for your workspace; and a 409 means the trigger is a draft or paused rather than active. Fix those separately from signing.

Frequently asked questions

I rotated the secret and now everything is 401.

The old secret stopped working immediately. Update your system with the new secret.

My signature looks right but still 401.

Sign the raw body before parsing, send the timestamp in seconds, and keep it within five minutes.

I get 403 or 409, not 401.

403 means the feature is off for your workspace; 409 means the trigger is not active. Neither is a signing issue.

Related articles

Did this answer your question?

More Support

Get more support from us