Quick overview
This workflow provides a hardened security layer for inbound POST webhooks, adding rate limiting, HMAC signature verification, replay/timestamp protection, payload validation, optional IP allow-listing, audit logging to an HTTP endpoint, and Slack alerting before passing accepted requests to your business logic.
How it works
- Receives an inbound POST request on an n8n Webhook with raw body capture enabled.
- Extracts request metadata (source IP, headers, raw body, parsed body, and timestamps) and applies a per-IP sliding-window rate limit, returning a 429 response when exceeded.
- Verifies the request’s HMAC-SHA256 signature against the raw body using a timing-safe comparison.
- Validates the timestamp to enforce an allowed clock skew and blocks replays by rejecting previously seen signature+timestamp pairs.
- Enforces basic payload rules by checking required fields and rejecting bodies that exceed the configured maximum size, and optionally blocks requests not in the configured IP/CIDR allow-list.
- Writes a structured audit record for every request to the configured HTTP endpoint and decides whether to proceed or reject based on the aggregated security verdict.
- If the request passes, it runs your “Business Logic” step and returns a 200 response, and if it fails, it tracks repeated failures per IP, posts an alert to Slack when the threshold is reached, and returns an appropriate error status.
Setup
- Configure the Webhook path as needed and copy the production webhook URL into the system sending requests.
- Replace the placeholder HMAC secret in the security configuration with a credential- or environment-backed value and ensure the sender uses the same secret, signature header, and timestamp header.
- Set your rate-limit, clock-skew, required-fields, max-payload-size, and (optionally) IP allow-list values in the security configuration.
- Set up an HTTP endpoint to receive audit logs and update the auditLogUrl to point to it.
- Add Slack credentials and set the target channel used for security alerts.