X-IMPRINT-HMAC-SIGNATURE header.
Header Format
TheX-IMPRINT-HMAC-SIGNATURE header is a comma-separated list of key/value pairs:
-
Timestamp (
t) – the time the request was sent, represented as seconds since January 1, 1970 (Unix epoch). -
Signature (
s) – the cryptographic hash used to verify the request. The header carries onesvalue per active signing token, so during a token rotation you will receive more than one.
During a signing token rotation
Verify signature
1
Extract the timestamp and signatures
-
Split the
X-IMPRINT-HMAC-SIGNATUREheader on commas (,) into its key/value pairs. -
Split each pair at the equals sign (
=). Taketas the timestamp and collect everysvalue into a list — there may be more than one.
2
Construct the message to sign
- Concatenate the timestamp , a period (
.), and the raw POST body as a string
1723493048, the message to sign would be:3
Compute the expected signature
- Use the signing token you were provided during event enrollment (hashed with SHA-256) to generate a Hash-based Message Authentication Code (HMAC).
- Apply HMAC using the SHA-256 algorithm to the message created in Step 2.
4
Compare signatures
-
Compare the computed signature with the
svalues from theX-IMPRINT-HMAC-SIGNATUREheader. Use a constant-time comparison. -
If any
svalue matches, the request is authentic and was sent by Imprint.
The signature and its timestamp are recomputed on every delivery attempt, so a retry of an
earlier event carries a current timestamp rather than the original one. Evaluate any freshness
window per request, and never use the signature or timestamp as a deduplication key. See
Delivery and retries.