New Connect feature: HMAC signatures for added security (2024)

    • What is an HMAC signature?
      • Securing your application
      • Documentation
      • The cryptography of HMAC signatures
      • Let’s talk in person at Momentum!

    Table of contents

    • What is an HMAC signature?
      • Securing your application
      • Documentation
      • The cryptography of HMAC signatures
      • Let’s talk in person at Momentum!
      New Connect feature: HMAC signatures for added security (4)

      By Larry Kluger and Joey Peng

      We’re pleased to announce a new feature for the Docusign Connect webhook system: HMAC signatures. The new feature is available May 22, 2019 for all developer sandbox (demo) accounts. It is scheduled to be enabled for all production accounts by May 31. The new feature will be available at no additional cost. HMAC provides an easier setup of Connect security compared to Mutual TLS and is much more secure than basic authentication.

      What is an HMAC signature?

      An HMAC (Hash-based Message Authentication Code) signature is a form of a digital signature. HMAC signatures start with a secret key that is shared between the sender (Docusign Connect) and the recipient (your application’s listener server).

      The Connect HMAC signatures provide two cryptographically strong information security guarantees:

      • Authentication of the sender. Assuming that you carefully secure the HMAC secret key(s), a verified HMAC signature guarantees that the message was sent by Docusign.

      • Message integrity. Verification of the HMAC signature also guarantees the message’s integrity, confirming that the message was not changed by an unauthorized third party. The included hash can also be used to double-check content correctness.

      Securing your application

      To maintain the security of the HMAC signatures, you should change your secret keys periodically. The usual practice is once every 1-2 years.

      Docusign strongly recommends that you consult with your organization’s Information Security department or a consultant before setting up a server on the Internet.

      Documentation

      Documentation of the HMAC feature is available on the Docusign Developer Center under Connect HMAC. Code examples are also being developed.

      The cryptography of HMAC signatures

      The Wikipedia article on HMAC Signatures is a good starting point for exploring the technology of HMAC signatures.

      Let’s talk in person at Momentum!

      Both Larry and Joey will be at the Docusign Momentum conference from June 11-13, 2019 in San Francisco. Come discuss Docusign Connect with us, and more. And as a developer, your registration fee is zero dollars. See you there!

      New Connect feature: HMAC signatures for added security (5)

      Larry Kluger

      DocuSign Lead Product Manager for Partner Platforms

      More posts from this author

      Discover what's new with Docusign IAM or start with eSignature for free

      New Connect feature: HMAC signatures for added security (16)

      New Connect feature: HMAC signatures for added security (2024)
      Top Articles
      How to Easily Create a Budget! - Take Control of Your Finances
      Decentralized Finance (DeFi) Development Services
      Layla Deline Leaks
      Secondary Action Required Va Claim
      Herbalism Guide Tbc
      How much does it cost to sell your Bitcoin?
      Binghamton Legacy Obits
      Shiawassee County 911 Active Events
      Itshayss
      „Wir sind dicht davor“: Rodri hält Streiks wegen zu vieler Spiele für denkbar
      The Financial Benefits of Earning a College Degree
      Hygeia: The Greek Goddess of Health | History Cooperative
      Bayview Freeborn Funeral Home | Albert Lea, Minnesota
      Succubus - Female Demon in Medieval Legend | Mythology.net
      7Starhd Movies
      Okpreps Forum
      Mugshots Key West
      Daily Press Escanaba Mi Obituaries
      Meg Turney Nipple
      Studentvue Lake Havasu
      Max Tl Nails
      Glenpool Fireworks 2023
      Villainess_Quest_Eng_Ver2.0 Rocks
      Volvo Heavy and Commercial Vehicle Fault Codes
      Samsung 9C8
      3036150070
      Lady Wicked Playground
      Myjohnshopkins Mychart
      Novant Mychart Nhrmc
      Qmf Bcbs Prefix
      Humbled And Subjugated Breeding Machine
      Vystar Cars For Sale
      Acura Rdx Screen Won't Turn On
      Now is The Perfect Time for Bethesda to Remake Morrowind
      Craigslist Edmond
      Uplift Grand Calendar
      Grams to Tablespoons Calculator - (g to tbsp Converter)
      Sinfuldeeds Married Latina
      Akali Op Gg Aram
      Salons Open Near Me Today
      Rockwall Bulk Pickup Zone 2
      King Von Autopsy Results
      The Telegram Births - March 2000
      The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
      Joy Ride 2023 Showtimes Near Amc Ward Parkway
      Grossest Cyst Removal Youtube
      Armslist Dayton
      Minecraft Astral Sorcery Guide | DiamondLobby
      Dusty Springfield - I Only Want To Be With You Lyrics
      What Is 5 Hours Away From Me
      Latest Posts
      Article information

      Author: Gregorio Kreiger

      Last Updated:

      Views: 6431

      Rating: 4.7 / 5 (57 voted)

      Reviews: 80% of readers found this page helpful

      Author information

      Name: Gregorio Kreiger

      Birthday: 1994-12-18

      Address: 89212 Tracey Ramp, Sunside, MT 08453-0951

      Phone: +9014805370218

      Job: Customer Designer

      Hobby: Mountain biking, Orienteering, Hiking, Sewing, Backpacking, Mushroom hunting, Backpacking

      Introduction: My name is Gregorio Kreiger, I am a tender, brainy, enthusiastic, combative, agreeable, gentle, gentle person who loves writing and wants to share my knowledge and understanding with you.