The Hive Inspect API is a work in progress. It is available to a small group of accounts today, and the release for everyone is coming very soon. To ask for early access, message us from the chat bubble in your dashboard.
How the signature works
Each message has two headers:v1 value is an HMAC-SHA256 of the timestamp, a dot, and the raw request body, using your signing secret as the key.
Verify a message
Read the raw body
Use the request body exactly as it arrived, before any JSON parsing. Parsing and re-writing the JSON changes the bytes and breaks the check.
Take the timestamp and signature from the header
Split
X-HiveInspect-Signature on the comma. t= is the timestamp and v1= is the signature.Compute the expected signature
Build the string
timestamp.body and compute its HMAC-SHA256 with your signing secret. Write the result as lowercase hex.Examples
rawBody must be the unparsed request body as a string. With Express, use express.raw({ type: "application/json" }) on the webhook route and pass req.body.toString().
Change the signing secret
Open the endpoint’s menu on the API Access page and choose New signing secret. Hive shows the new secret once.Things to know
- Each endpoint has its own secret. Changing one does not affect the others.
- Hive shows a secret once. If you lose it, create a new one.
- A retry has a new timestamp and a new signature. The body and the event
idstay the same.

