get
https://{yourinstance}.makaira.io/app//validate
Check if a given HMAC is valid. This request is part of the Authorization-Flow, when you want to use the Auth-Token inside of your application.
Validates an app's HMAC signature. This endpoint is part of the authorization flow used when an external app wants to verify a Makaira-generated HMAC before accepting a request.
Requires the app:validate:read or app.read permission.
Request
POST /app/{slug}/validate
Path Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
slug | string | Yes | The slug of the app to validate. |
Headers
| Header | Value |
|---|---|
Authorization | Bearer <token> |
Content-Type | application/json |
Request Body
| Field | Type | Required | Description |
|---|---|---|---|
nonce | string | Yes | A random nonce value used when generating the HMAC. |
hmac | string | Yes | The HMAC value to validate, provided by the external app. |
makairaHmac | string | Yes | The Makaira-generated HMAC computed from the app's clientSecret and the nonce. |
Example Request
{
"nonce": "abc123xyz",
"hmac": "external-hmac-value",
"makairaHmac": "makaira-computed-hmac"
}Response
Always returns HTTP 200. The valid field indicates whether the HMAC is valid.
Response Body
| Field | Type | Description |
|---|---|---|
valid | boolean | true if the HMAC is valid, false otherwise. |
Example Response (valid)
{
"valid": true
}Example Response (invalid)
{
"valid": false
}
