Sign In

@bolthub/verify

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@bolthub/verify

Verify bolthub gateway signatures on your origin server — Express, Fastify, or generic Node.js middleware

latest
Source
npmnpm
Version
0.1.2
Version published
Weekly downloads
8
60%
Maintainers
1
Weekly downloads
 
Created
Source

@bolthub/verify

Verify that incoming requests to your origin server were proxied through the BoltHub gateway. Zero dependencies; uses only Node.js built-in crypto.

Install

npm install @bolthub/verify

Quick Start (Express)

import { expressHmacMiddleware } from "@bolthub/verify";

app.use(
  expressHmacMiddleware({
    secrets: [process.env.HMAC_SECRET!],
  })
);

Requests without a valid X-Gateway-Signature header are rejected with 403.

Verification Methods

BoltHub supports two verification methods:

The gateway signs every request with HMAC-SHA256 over the canonical payload METHOD\nPATH\nTIMESTAMP\nNONCE\nBODY. This prevents replay attacks and body tampering.

import { verifyGatewaySignature } from "@bolthub/verify";

const result = verifyGatewaySignature(
  {
    method: req.method,
    path: req.path,
    headers: req.headers,
    body: rawBody,
  },
  { secrets: [process.env.HMAC_SECRET!] }
);

if (!result.valid) {
  return res.status(403).json({ error: result.error });
}

Shared Secret

A simpler method where the gateway sends a static X-Gateway-Secret header. No replay protection, but easier to set up.

import { verifyGatewaySecret } from "@bolthub/verify";

const result = verifyGatewaySecret(
  { method: req.method, path: req.path, headers: req.headers },
  { secrets: [process.env.GATEWAY_SECRET!] }
);

Secret Rotation

Both methods accept an array of secrets, allowing zero-downtime rotation:

expressHmacMiddleware({
  secrets: [currentSecret, previousSecret],
  maxAgeMs: 30_000,
});

The library tries each secret in order and accepts the first match.

API Reference

ExportDescription
verifyGatewaySignature(request, options)Verify HMAC-SHA256 signature headers
verifyGatewaySecret(request, options)Verify shared secret header
expressHmacMiddleware(options)Express/Connect middleware for HMAC verification
expressSecretMiddleware(options)Express/Connect middleware for shared secret verification
VerifyOptionsOptions: secrets, maxAgeMs
VerifyResultResult: { valid: boolean; error?: string }
RequestLikeMinimal request shape accepted by verify functions

License

MIT

Keywords

bolthub

FAQs

Package last updated on 10 Jun 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts