2026-07-10 · 4 min read · ListBridge engineering
Why ListBridge signs every API request.
Bearer keys identify the workspace; versioned HMAC signatures bind the complete request target and payload.
A bearer key is enough to identify a caller, but it does not prove that the request arrived unchanged. ListBridge therefore signs a versioned canonical request with a per-key HMAC secret.
The request contract
Every authenticated request includes an API key, a Unix timestamp and a `v1` SHA-256 HMAC signature. The canonical payload binds the HTTP method, canonical path and query, the exact body hash, and the idempotency-key hash. The server rejects expired timestamps, invalid signatures and conflicting idempotent replays before any marketplace action begins.
Test and live keys use the same contract. The difference is where the action goes: test keys use deterministic sandbox drivers, while live keys require an active subscription before any marketplace processing.