Skip to content

Signing and verification

Verify HMAC-SHA256 over v1.<unix_seconds>.<exact_raw_request_body>. Use the exact raw request body bytes. Parsing and reserializing JSON changes the signed input.

Support the generated overlap window for current and previous secrets, then remove the previous secret when the contract says the overlap has ended.