
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@korala/auth
Advanced tools
HMAC authentication utilities for the Korala document signing API.
npm install @korala/auth
import { signRequest } from '@korala/auth';
const { signature, timestamp } = signRequest({
method: 'POST',
path: '/api/v1/documents',
body: JSON.stringify({ name: 'Contract' }),
secret: 'your-api-secret',
});
// Use in request headers
fetch('https://api.korala.ai/api/v1/documents', {
method: 'POST',
headers: {
'X-API-Key': 'your-api-key-id',
'X-Timestamp': String(timestamp),
'X-Signature': signature,
'Content-Type': 'application/json',
},
body: JSON.stringify({ name: 'Contract' }),
});
import { verifyWebhookSignature } from '@korala/auth';
const isValid = verifyWebhookSignature({
payload: rawBody,
signature: headers['x-signature'],
timestamp: headers['x-timestamp'],
secret: webhookSecret,
});
Note: Most users should use
@korala/api-clientwhich handles authentication automatically. This package is for advanced use cases or custom HTTP clients.
| Function | Description |
|---|---|
signRequest(opts) | Generate HMAC signature + timestamp for an API request |
verifySignature(opts) | Verify an incoming API request signature |
signWebhookPayload(payload, secret) | Sign a webhook payload |
verifyWebhookSignature(opts) | Verify a webhook delivery signature |
computeSignature(message, secret) | Low-level HMAC-SHA256 computation |
getTimestamp() | Get current Unix timestamp in seconds |
isTimestampValid(timestamp, maxAge?) | Check if a timestamp is within the allowed window |
Full documentation at docs.korala.ai.
MIT
FAQs
HMAC authentication utilities for the Korala document signing API
We found that @korala/auth demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.