Every request your system sends to a trigger's Webhook URL must be signed, so Mando can confirm it really came from you. Mando verifies the signature and rejects anything that does not match.
The two headers
Send both of these on every request:
- X-Mando-Timestamp: the current unix time in seconds.
- X-Mando-Signature: sha256= followed by the hex HMAC-SHA256 of the string trigger id : timestamp : raw body, using your signing secret.
Get the details from the card
The trigger's Connection card shows the exact Webhook URL, your Signing secret, and this recipe in a How to sign panel, including your trigger id. Sign the raw request body before any parsing, and keep the timestamp within five minutes of now.
Rotate the secret if it leaks
If your signing secret is exposed, use Rotate on the Connection card to mint a new one. The old secret stops working immediately, so update your system with the new value right away.
Frequently asked questions
What exactly do I sign?
The string trigger id, timestamp and raw body joined by colons, with HMAC-SHA256 and your secret, as hex.
Raw body or parsed?
The raw body bytes, before parsing. A re-serialized body will not match.
My request is rejected.
See the article on trigger 401 errors for each cause and fix.
