Skip to main content

Build Status Coverage Status PyPI version

About

SignIt is a helper-library to create and verify HMAC (HMAC-SHA256 by default) signatures that could be used to sign requests to the APIs.


Use cases

On the client side you could

  • sign your requests using signit.signature.create()

On the server side you could

  • parse a signature retrieved from request header or query string using signit.signature.parse()

  • verify retrieved signature using signit.signature.verify()

  • generate access and secret keys for client using signit.key.generate()


Example of usage (client)

import datetime
import requests
import signit

ACCESS_KEY = 'MY_ACCESS_KEY'
SECRET_KEY = 'MY_SECRET_KEY'

def create_user(user: dict) -> bool:
    msg = str(datetime.datetime.utcnow().timestamp())
    auth = signit.signature.create(MY_ACCESS_KEY, MY_SECRET_KEY, msg)
    headers = {
        'Unix-Timestamp': msg,
        'Authorization': auth,
    }
    r = requests.post('http://example.com/users', json=user, headers=headers)
    return r.status_code == 201

The Authorization header will look like

Authorization: HMAC-SHA256 MY_ACCESS_KEY:0947c88ce16d078dde4a2aded1fe4627643a378757dccc3428c19569fea99542

Example of usage (server)

The server has issued an access key and a secret key for you. And only you and the server know the secret key.

So that the server could identify you by your public access key and ensure that you used the secret key to produce a hash of the message in this way:

# ...somewhere in my_api/resources/user.py
import signit
from aiohttp import web
from psycopg2 import IntegrityError

async def post(request):
    message = request.headers['Unix-Timestamp']
    signature = request.headers['Authorization']
    prefix, access_key, hmac_digest = signit.signature.parse(signature)
    secret_key = await get_secret_key_from_db(access_key)
    if not signit.signature.verify(hmac_digest, secret_key, message):
        raise web.HTTPUnauthorized('Invalid signature')
    try:
        await create_user(request)
    except IntegrityError:
        raise web.HTTPConflict()
    return web.HTTPCreated()

Additionally if you use a Unix-Timestamp as a message message the server could check if the request is too old and deny with 401 to protect against “replay attacks”.

Release files for signit 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for signit 0.3.0
File Size Uploaded
signit-0.3.0.tar.gz 3.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for signit 0.3.0
File Interpreter ABI Platform
signit-0.3.0-py2.py3-none-any.whl Python 2, Python 3 none any Details

Total release size: 10.2 kB

Release files / signit-0.3.0.tar.gz

Download URL signit-0.3.0.tar.gz
Size 3.9 kB
Tags Source
SHA-256 checksum
How to use checksums
c97a65dd336b37391d8197b7af0a7a9da856366b62ce35608b20bcf2185ba936
BLAKE2b-256 checksum
How to use checksums
1748a89a63fe7f5b0a7faa093e5cd3bcb95018fb836a6372987988f7c2f7fa36
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / signit-0.3.0-py2.py3-none-any.whl

Download URL signit-0.3.0-py2.py3-none-any.whl
Size 6.3 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
61edddf9fb8d925f043b477a63ebcbcfb999c2ddb27726309a08855e6531bf4f
BLAKE2b-256 checksum
How to use checksums
73f909f481e8536cbf43fb2bf90a06742bd4173847eda6108b6857dca6ecb97e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

0.3.0 This release

2 release files

0.2.0

2 release files

0.1.3

1 release file

0.1.2

1 release file

0.1.1

1 release file

0.1.0

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page