Skip to main content
Imprint provides signed webhooks to ensure authenticity and verify that the webhook requests originate from our servers. You’ll receive a unique event signing token while enrolling in event notifications, and each event request includes a signature in the X-IMPRINT-HMAC-SIGNATURE header.

Header Format

The X-IMPRINT-HMAC-SIGNATURE header is a comma-separated list of key/value pairs:
  • Timestamp (t) – the time the request was sent, represented as seconds since January 1, 1970 (Unix epoch).
  • Signature (s) – the cryptographic hash used to verify the request. The header carries one s value per active signing token, so during a token rotation you will receive more than one.
During a signing token rotation
Parse the header by splitting on commas and reading every s value — do not assume the header contains exactly one signature. A verifier that only checks the first s will begin rejecting valid events partway through a rotation.

Verify signature

1

Extract the timestamp and signatures

  • Split the X-IMPRINT-HMAC-SIGNATURE header on commas (,) into its key/value pairs.
  • Split each pair at the equals sign (=). Take t as the timestamp and collect every s value into a list — there may be more than one.
2

Construct the message to sign

  • Concatenate the timestamp , a period (.), and the raw POST body as a string
and the timestamp is 1723493048, the message to sign would be:
3

Compute the expected signature

  • Use the signing token you were provided during event enrollment (hashed with SHA-256) to generate a Hash-based Message Authentication Code (HMAC).
  • Apply HMAC using the SHA-256 algorithm to the message created in Step 2.
4

Compare signatures

  • Compare the computed signature with the s values from the X-IMPRINT-HMAC-SIGNATURE header. Use a constant-time comparison.
  • If any s value matches, the request is authentic and was sent by Imprint.
The signature and its timestamp are recomputed on every delivery attempt, so a retry of an earlier event carries a current timestamp rather than the original one. Evaluate any freshness window per request, and never use the signature or timestamp as a deduplication key. See Delivery and retries.