Skip to main content
CollabOS signs the exact raw JSON request body with HMAC-SHA256. Each delivery includes: The signed value is:
Expected signature:

Node.js example

Verify against the raw request body, not a parsed-and-reserialized JSON object. Re-serialization can change bytes and invalidate the signature.
For additional replay protection, reject timestamps that are too old for your application and deduplicate deliveries using X-Collabos-Delivery.