Skip to content
Ask a question in your own words

Sign trigger webhook requests

Sign every request to your trigger URL with two headers, a timestamp and an HMAC-SHA256 signature over the raw body, using the secret from the Connection card.

Written by: Malaz Madani42 minutes ago2 min read

Every request your system sends to a trigger's Webhook URL must be signed, so Mando can confirm it really came from you. Mando verifies the signature and rejects anything that does not match.

The two headers

Send both of these on every request:

  • X-Mando-Timestamp: the current unix time in seconds.
  • X-Mando-Signature: sha256= followed by the hex HMAC-SHA256 of the string trigger id : timestamp : raw body, using your signing secret.

Get the details from the card

The trigger's Connection card shows the exact Webhook URL, your Signing secret, and this recipe in a How to sign panel, including your trigger id. Sign the raw request body before any parsing, and keep the timestamp within five minutes of now.

Rotate the secret if it leaks

If your signing secret is exposed, use Rotate on the Connection card to mint a new one. The old secret stops working immediately, so update your system with the new value right away.

Frequently asked questions

What exactly do I sign?

The string trigger id, timestamp and raw body joined by colons, with HMAC-SHA256 and your secret, as hex.

Raw body or parsed?

The raw body bytes, before parsing. A re-serialized body will not match.

My request is rejected.

See the article on trigger 401 errors for each cause and fix.

Related articles

Did this answer your question?

More Support

Get more support from us