Back to Blog
Engineering

James Liu7 min
Alt+F4

When your computer use agent runs a task, Coasty streams status updates via Server-Sent Events to your webhook_url. Receiving those events is only half the battle. Malicious actors could forge requests to your endpoint, or network issues could corrupt data in transit. Coasty solves this by HMAC signing webhook payloads so you can verify authenticity and integrity before acting on them.

HMAC signatures in the Computer Use API

  • Coasty signs webhook payloads with an HMAC-SHA256 hash using your API key as the secret.
  • The signature is sent in the Coasty-Signature header with this format: t=unix_timestamp,v1=hex_digest.
  • You read your API key from the COASTY_API_KEY environment variable and never hardcode it.
  • The header is present on all webhook events from POST /v1/runs and GET /v1/runs/{id}/events.
  • If the signature verification fails, reject the event and log the request_id for debugging.
python
import hmac
import hashlib
import os
import json
from flask import Flask, request, jsonify

app = Flask(__name__)
API_KEY = os.getenv("COASTY_API_KEY")

@app.route("/webhook", methods=["POST"])
def webhook():
    # Retrieve the Coasty-Signature header
    header = request.headers.get("Coasty-Signature")
    if not header:
        return jsonify({"error": "Missing signature header"}), 401

    # Parse the header: t=unix,v1=hex
    timestamp, sig_hex = header.split(",")
    timestamp = int(timestamp.split("=")[1])
    received_sig = sig_hex.split("=")[1]
    
    # Verify timestamp freshness (within 5 minutes)
    if abs(time.time() - timestamp) > 300:
        return jsonify({"error": "Stale signature"}), 401
    
    # Get the raw request body
    payload = request.get_data()
    
    # Recompute HMAC-SHA256
    computed = hmac.new(API_KEY.encode(), payload, hashlib.sha256).hexdigest()
    
    if not hmac.compare_digest(computed, received_sig):
        return jsonify({"error": "Invalid signature"}), 401
    
    # Payload verified - deserialize
    event = json.loads(payload.decode("utf-8"))
    request_id = event.get("request_id")
    state = event.get("state")
    # Your business logic here, e.g., store state, notify downstream services
    return jsonify({"status": "ok", "request_id": request_id, "state": state})

if __name__ == "__main__":
    app.run(port=8080)

How to enable webhooks

  • POST /v1/runs accepts a webhook_url and on_awaiting_human parameter.
  • Coasty sends SSE events to that URL whenever status changes (queued, running, succeeded, failed, etc.).
  • You must implement a server that exposes an HTTPS endpoint accepting POST requests.
  • The server must echo 200 OK and return JSON for valid signatures.
  • Use a load balancer or CDN if you need high availability.

Key fields for webhook payloads

  • request_id: unique identifier for the request, returned on POST /v1/runs.
  • run_id: identifier returned by POST /v1/runs, used with GET /v1/runs/{id} and GET /v1/runs/{id}/events.
  • state: one of queued, running, awaiting_human, succeeded, failed, cancelled, timed_out.
  • error_code and error_message are present when state is failed.
  • timestamp or last_event_id help you handle reconnections in SSE flows.

Always verify the Coasty-Signature header before trusting a webhook payload.

Where this beats brittle automation

  • Webhook signatures ensure that only Coasty-generated events reach your backend, preventing spoofed runs.
  • Unlike brittle XPATH or CSS selectors that break on UI changes, Coasty uses computer use to interact with real desktops and browsers.
  • With HMAC verification, you can safely integrate with downstream systems like databases, chat platforms, or CI pipelines.
  • Rate limits and billing are tied to run steps ( billed $0.05 per agent step), so accurate event tracking is critical.
  • The Coasty Computer Use API lets you drive real machines, not just mocked endpoints, making even complex workflows reliable.

Now that you can verify webhook payloads with HMAC signatures, you can confidently build production-grade integrations around Coasty's computer use agent. Start by enabling webhooks in your run configurations and implement a simple verification endpoint like the example above. Want to try it yourself? Get your API key at https://coasty.ai/developers to start building secure, event-driven automation.

© 2026 Coasty

Backed byYCombinator