Reference
Request signing
We sign outbound requests we make to your target URLs with a HMAC signature using a shared secret key. This allows you to verify that the request was made by Plain and not a third party.
How to verify
Your workspace has a global HMAC secret, this secret can be viewed and (re)generated by workspace admins in Settings → Request signing.
If you have a HMAC secret set up, when you receive a request from Plain you will see a header Plain-Request-Signature
with the HMAC signature.
You can verify this signature by hashing the request body with your HMAC secret and comparing it to the signature in the header.
The signature is a SHA-256 hash of the request body, encoded as a hexadecimal string.
Node example
Was this page helpful?