hmac
Safeguard articles tagged "hmac" — guides, analysis, and best practices for software supply chain and application security.
4 articles
Five Ways a Webhook Receiver Goes Wrong
It is a public, unauthenticated endpoint that performs privileged actions on a JSON body from the internet. Everyone knows this, and most implementations still get one of five things wrong in ways that pass every test.
Webhook security best practices: HMAC signing, replay protection, and IP allowlisting
Stripe gives webhook signatures a 5-minute tolerance window; GitHub signs with HMAC-SHA256. Here's how to build inbound and outbound webhooks that survive both.
Verifying webhook signatures correctly
Stripe gives you a 5-minute replay window and GitHub a raw-body HMAC — but most outages trace back to one bug: verifying JSON after it's been re-serialized.
HMAC
HMAC is a cryptographic construct that combines a hash function with a secret key to verify both the integrity and authenticity of a message.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.