How to validate a webhook message using HMAC/Signing Key in Azure Logic App?

Viewed 186

I have developed an Azure Logic App with Http trigger in that I have used Service Bus Send Message action for posting messages to Azure Service Bus Queue.

I have configured the webhook with the Logic App endpoint in the third-party system. I’m getting the messages with Signing Key from third-party system. I want to validate the incoming message using Signing Key getting it from third-party system before posting messages to Azure Service Bus Queue through the Azure Logic App.

I have referred this documentation for validating the webhook message. But this documentation contains the explanation in .Net.

Is it Possible to validate/authenticate Signing Key in the Azure Logic App?

1 Answers
  • If you want to connect HMAC through Logic app you need to need to create a function app and call from function app so that you can use Signing Key for sending messages to Service Bus

Below is the sample function code where you can use this for generating a HMAC key

const CryptoJS = require("crypto-js");
module.exports = async function (context, req) {
    context.log('JavaScript HTTP trigger function processed a request.');
    //get the data used to sign from request body
      const data = req.body.data

   // sign
   const str = CryptoJS.HmacSHA256(
     CryptoJS.enc.Utf8.parse(req.body.data),,

    "key"
  );
     const sig = CryptoJS.enc.Base64.stringify(str);

     context.res = {
       
        body: sig // return the hash
     };
}
  • Now, you need to call Azure Function from Logic App to generate Key
  • Need to call API from Azure Function for that you can use hash data

Here is the expression to call has data @{body('<action name>')}

Also you need to call below values in headers in HTTP connector

Accept    =      Application/json
Accept   = application/json
api-auth-id = (your function id)
api-auth-signature = @{body('getkey')}

enter image description here

Now you can execute your code to get your result. Also for further details you can check the below SO for related discussion.

Related