Validate app

Check if a given HMAC is valid. This request is part of the Authorization-Flow, when you want to use the Auth-Token inside of your application.

Validates an app's HMAC signature. This endpoint is part of the authorization flow used when an external app wants to verify a Makaira-generated HMAC before accepting a request.

Requires the app:validate:read or app.read permission.

Request

POST /app/{slug}/validate

Path Parameters

ParameterTypeRequiredDescription
slugstringYesThe slug of the app to validate.

Headers

HeaderValue
AuthorizationBearer <token>
Content-Typeapplication/json

Request Body

FieldTypeRequiredDescription
noncestringYesA random nonce value used when generating the HMAC.
hmacstringYesThe HMAC value to validate, provided by the external app.
makairaHmacstringYesThe Makaira-generated HMAC computed from the app's clientSecret and the nonce.

Example Request

{
  "nonce": "abc123xyz",
  "hmac": "external-hmac-value",
  "makairaHmac": "makaira-computed-hmac"
}

Response

Always returns HTTP 200. The valid field indicates whether the HMAC is valid.

Response Body

FieldTypeDescription
validbooleantrue if the HMAC is valid, false otherwise.

Example Response (valid)

{
  "valid": true
}

Example Response (invalid)

{
  "valid": false
}
Path Params
string
required

The slug of an existing app

Headers
string
required

Makaira Instance ID

Responses

Language
Credentials
Bearer
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json