Secure n8n Inbound Webhook with HMAC, Rate Limits & Slack
Secure n8n Inbound Webhook with HMAC, Rate Limits & Slack
Regular price
£55.99
Regular price
£55.99
Sale price
Unit price
/
per
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
Couldn't load pickup availability
🔥
128+ Sold
Popular with n8n builders
âš¡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
Secure n8n Inbound Webhook with HMAC, Rate Limits & Slack
Regular price
£55.99
Regular price
£55.99
Sale price
Unit price
/
per
Harden your n8n inbound webhooks with HMAC security, rate limits, and Slack alerts
This n8n workflow secures an inbound webhook with HMAC-SHA256 signature verification, replay/timestamp protection, per-IP sliding-window rate limiting, optional CIDR IP allow-listing, and Slack-based security alerting—so only legitimate requests reach your business logic.
What this workflow does
- Receives inbound POST requests on your n8n webhook endpoint with raw body capture enabled.
- Enforces per-IP sliding-window rate limits and immediately returns HTTP 429 when a sender exceeds the threshold.
- Verifies HMAC signatures (HMAC-SHA256) using a configured request header and a timing-safe comparison against the raw payload.
- Blocks replay attacks by validating request timestamps (with allowed clock skew) and rejecting previously seen signature+timestamp pairs.
- Validates required fields and applies a maximum payload size check before processing.
- Optionally allows only approved IPs using a CIDR-aware allow-list, returning the appropriate verdict status code.
- Writes structured audit logs for every request to a configurable HTTP endpoint, including verdict details and a truncated hash of the body.
- If the request fails, it tracks repeated failures per IP and posts an alert to Slack once a threshold is exceeded; successful requests run your placeholder Business Logic step and return 200.
Use cases
- SaaS operators protecting webhook endpoints from abuse, replay attempts, and request floods.
- Automation engineers integrating third-party services that require signed webhook verification.
- Teams needing auditability for inbound webhook security events via an HTTP logging endpoint.
Technical details
- n8n nodes: webhook, code, if, set, no op, and slack.
- Core protections: rate limiting, HMAC-SHA256 verification, timestamp validation, replay prevention, payload field checks and size limits, and CIDR IP allow-listing.
- Security monitoring: Slack alerts after repeated failure thresholds.
