Skip to main content

bolthub-verify

Verify bolthub gateway signatures on your origin server. Supports Flask, Django, and FastAPI out of the box.

Install

pip install bolthub-verify

Quick start (Flask)

from bolthub_verify import flask_hmac_middleware

app.before_request(flask_hmac_middleware("your-hmac-secret-from-dashboard"))

Quick start (FastAPI)

from fastapi import Depends
from bolthub_verify import fastapi_hmac_middleware

verify = fastapi_hmac_middleware("your-hmac-secret-from-dashboard")

@app.get("/protected")
async def protected(_=Depends(verify)):
    return {"ok": True}

Quick start (Django)

# settings.py
MIDDLEWARE = [
    "bolthub_verify.django_hmac_middleware",
    # ...
]
BOLTHUB_HMAC_SECRETS = ["current-secret", "previous-secret"]

Secret rotation

Pass an array of secrets (current + previous) to support zero-downtime rotation:

flask_hmac_middleware(["new-secret", "old-secret"])

Low-level API

from bolthub_verify import verify_gateway_signature

result = verify_gateway_signature(
    method="GET",
    path="/v1/data",
    signature=request.headers["X-Gateway-Signature"],
    timestamp=request.headers["X-Gateway-Timestamp"],
    nonce=request.headers["X-Gateway-Nonce"],
    body="",
    secrets="your-secret",
)
if not result.valid:
    print(result.error)

Metadata

Release files for bolthub-verify 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for bolthub-verify 0.1.1
File Size Uploaded
bolthub_verify-0.1.1.tar.gz 3.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for bolthub-verify 0.1.1
File Interpreter ABI Platform
bolthub_verify-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 7.3 kB

Release files / bolthub_verify-0.1.1.tar.gz

Download URL bolthub_verify-0.1.1.tar.gz
Size 3.8 kB
Tags Source
SHA-256 checksum
How to use checksums
f9678b5fd29d63e7ddc009609cc3b971e527a6e0f8d092b8afa76780f08f555a
BLAKE2b-256 checksum
How to use checksums
46682be0e1e6fa29db04a0a9041f54e9b15afead2589e461b285ad6184ddfc58
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 10, 2026.

Transparency log

Release files / bolthub_verify-0.1.1-py3-none-any.whl

Download URL bolthub_verify-0.1.1-py3-none-any.whl
Size 3.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
67144b89b14433778c405504ae7ec2e65b73d9bd44eb02438adbd6a5653560fc
BLAKE2b-256 checksum
How to use checksums
7e4b71ab09de17496b48970f53bce76a9f90a396e917a205ec8913520de52219
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 10, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page