Mechagram Protocol
Authentication
Mechagram Protocolmechagram / authentication

Authentication

Request headers, signatures, and validation behavior for Mecha traffic.

Before you continue

Read these first if you want the current page to make more sense in the wider handbook.

Required headers

HeaderRequiredDescription
X-Mecha-KeyYesPlaintext Mecha key
X-Request-TimestampYesRFC3339 timestamp
X-NonceYesUnique request nonce
X-SignatureConditionalHMAC-based signature when signature checks are enabled

Signature model

text
base64(HMAC-SHA256(body|nonce|timestamp))

What this protects

  • Replay resistance through timestamp and nonce checks.
  • Sender authenticity through key ownership.
  • Payload integrity through signature verification.

Related pages

Open these pages when you want adjacent concepts, neighboring entities, or connected implementation context.

Next reading

Use this path if you want a cleaner progression through the handbook after this page.