# Mender Webhook Signature

**URL:** <https://hub.mender.io/t/mender-webhook-signature/6041>\
**Category:** General Discussions\
**Created:** [July 27, 2023, 5:00pm UTC](https://hub.mender.io/t/mender-webhook-signature/6041 "2023-07-27T17:00:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rowansdabomb](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/rowansdabomb/32/1949_2.png) [@Rowansdabomb](https://hub.mender.io/u/Rowansdabomb)\
**Post date:** [July 27, 2023, 5:00pm UTC](https://hub.mender.io/t/mender-webhook-signature/6041/1 "2023-07-27T17:00:47Z")

</div>

I’ve been attempting to implement a webhook server integration.

I’m able to setup the webhook fine, but I am unable to authenticate with the `X-men-signature` header.

re: [Webhooks | Mender documentation](https://docs.mender.io/server-integration/webhooks#signature-header)

> If you specify a secret, an integrity check is calculated and located in the `X-Men-Signature-Payload` header, which contains the HMAC-SHA256 of the payload using the configured secret.

First, it seems there is no `X-Men-Signature-Payload` header, but I’ve assumed this to be the `X-Men-Signature` header that is associated with the request.

Now for my issue, I setup a test webhook integration with a simple hex string secret, say `abcd`. On my server, I sign the payload with hmac-256 using the `abcd` secret as the key.

In a flask server (python 3.10) this looks like:

```python3
    signature = request.headers["X-Men-Signature"]
    secret = get_mender_webhook_secret()
    payload = request.get_data()
    message_hmac = hmac.new(secret.encode(), msg=payload, digestmod=hashlib.sha256)
    valid = hmac.compare_digest(message_hmac.hexdigest(), signature.encode())

```

However, the hmac hexdigest does not match the signature from the request headers.

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![Rowansdabomb](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/rowansdabomb/32/1949_2.png) [@Rowansdabomb](https://hub.mender.io/u/Rowansdabomb)\
**Post date:** [July 27, 2023, 6:11pm UTC](https://hub.mender.io/t/mender-webhook-signature/6041/2 "2023-07-27T18:11:42Z")

</div>

I found the solution with the help of my team, and parsing through the mender source.

the secret first needs to be decoded as hex: `base64.b16decode(get_mender_webhook_secret())`

so a working version of the above code is:

```auto
signature = request.headers["X-Men-Signature"]
    secret = base64.b16decode(get_mender_webhook_secret())
    payload = request.get_data()
    message_hmac = hmac.new(secret, msg=payload, digestmod=hashlib.sha256)
    valid = hmac.compare_digest(message_hmac.hexdigest(), signature.encode())

```

---

<div class="post-metadata">

**Author:** ![TheYoctoJester](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/theyoctojester/32/1444_2.png) [@TheYoctoJester](https://hub.mender.io/u/TheYoctoJester)\
**Post date:** [July 28, 2023, 6:47am UTC](https://hub.mender.io/t/mender-webhook-signature/6041/3 "2023-07-28T06:47:47Z")

</div>

Thanks a lot for sharing @Rowansdabomb!

Greetz,  
Josef
