Skip to main content
The Hive Inspect API is a work in progress. It is available to a small group of accounts today, and the release for everyone is coming very soon. To ask for early access, message us from the chat bubble in your dashboard.
Anyone who learns your endpoint URL could send it a fake message. Hive signs every webhook with your endpoint’s signing secret, so you can check that a message is real before you act on it.

How the signature works

Each message has two headers:
The v1 value is an HMAC-SHA256 of the timestamp, a dot, and the raw request body, using your signing secret as the key.

Verify a message

1

Read the raw body

Use the request body exactly as it arrived, before any JSON parsing. Parsing and re-writing the JSON changes the bytes and breaks the check.
2

Take the timestamp and signature from the header

Split X-HiveInspect-Signature on the comma. t= is the timestamp and v1= is the signature.
3

Compute the expected signature

Build the string timestamp.body and compute its HMAC-SHA256 with your signing secret. Write the result as lowercase hex.
4

Compare the two

Use a constant-time comparison. If they differ, reply 400 and ignore the message.
5

Check the age

Reject a message whose timestamp is more than 5 minutes old. This stops someone from re-sending a message they captured earlier.

Examples

In Node.js, rawBody must be the unparsed request body as a string. With Express, use express.raw({ type: "application/json" }) on the webhook route and pass req.body.toString().

Change the signing secret

Open the endpoint’s menu on the API Access page and choose New signing secret. Hive shows the new secret once.
The old secret stops working right away. Messages sent after the change are signed with the new secret, including retries of earlier events. Update your receiver as soon as you create the new secret.

Things to know

  • Each endpoint has its own secret. Changing one does not affect the others.
  • Hive shows a secret once. If you lose it, create a new one.
  • A retry has a new timestamp and a new signature. The body and the event id stay the same.
Last modified on October 2, 2026