- Purpose
- Ensure only genuine, fresh events mutate your data.
- Prerequisites
- Signing secret
- Architecture
- Signature covers timestamp and raw body; verification must use the raw bytes.
Configuration
| Replay window | 300 seconds |
Implementation steps
- 01Capture the raw body before JSON parsing
- 02Compute HMAC and compare in constant time
- 03Reject stale timestamps
- 04Rotate the secret with dual-accept
Testing procedure
- Send a tampered payload and assert 401
Troubleshooting
Signature never matches
A body parser re-serialised the payload. Verify against raw bytes.