Request signatures

All outgoing HTTP requests has the User-Agent header set to Serialized/1.0 and includes a Serialized specific signature header that can be used to verify the request’s authenticity.

The header is named Serialized-Request-Signature and contains a HMAC calculated using the HmacSHA256 algorithm, specified in RFC 2104 and FIPS PUB 180-2.

Different request types

Different requests have different signatures, that you can use to verify the outgoing request from Serialized to your backend.

Request type

Signed data


Reaction definition name


Projection definition name


import org.apache.commons.codec.digest.*;
public Response performNotification(@Context HttpHeaders headers, String body) {
String expectedReactionName = "notify-on-order-shipped";
String receivedSignature = headers.getHeaderString("Serialized-Request-Signature");
String calculatedSignature = new HmacUtils(HMAC_SHA_256, expectedReactionName).hmacHex(body);
if (!calculatedSignature.equals(receivedSignature)) {
throw new WebApplicationException(BAD_REQUEST);