Signature Verification
Webhook Signatures
Generate and verify HMAC-SHA256 or HMAC-SHA512 signatures using timestamped canonical strings and transient local-only secrets.
Public-safe Work
- Generate timestamped HMAC header
- Verify signature tolerance
- Explain digest mismatch
- Confirm secretPersisted=false
Protected Boundary
Persistent mutation, third-party delivery, raw private detail, replay, cancel, publish, and sync actions require PLATPHORM_API_KEY.
Authorization: Bearer $PLATPHORM_API_KEY
X-PlatPhorm-API-Key: $PLATPHORM_API_KEYAPI Surface
POST /api/v1/signatures/generatePOST /api/v1/signatures/verifyPOST /api/v1/signatures/explainGET /api/v1/signatures/algorithmsLifecycle Context
1. Define event type
Name the event, version it, and wrap it in the PlatPhorm event envelope.
2. Define event contract
Attach JSON Schema or an AsyncAPI-compatible event contract before delivery.
3. Register endpoint
Validate endpoint URLs with SSRF protection; server persistence is protected.
4. Generate payload
Create a positive sample, negative sample, or local event payload from a template.
5. Sign payload
Build the canonical string and HMAC header without storing the raw secret.
6. Send event
Protected sends create an event, delivery, async job, attempt, and trace-linked evidence.
platphormctl
platphormctl site inspect webhooksplatphormctl mcp validate webhooksplatphormctl policy inspect webhooksplatphormctl webhooks events