{"product_id":"secure-n8n-inbound-webhook-with-hmac-rate-limits-slack","title":"Secure n8n Inbound Webhook with HMAC, Rate Limits \u0026 Slack","description":"\u003ch3\u003eHarden your n8n inbound webhooks with HMAC security, rate limits, and Slack alerts\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow secures an inbound webhook with \u003cstrong\u003eHMAC-SHA256 signature verification\u003c\/strong\u003e, \u003cstrong\u003ereplay\/timestamp protection\u003c\/strong\u003e, \u003cstrong\u003eper-IP sliding-window rate limiting\u003c\/strong\u003e, optional \u003cstrong\u003eCIDR IP allow-listing\u003c\/strong\u003e, and \u003cstrong\u003eSlack-based security alerting\u003c\/strong\u003e—so only legitimate requests reach your business logic.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eReceives inbound POST requests\u003c\/strong\u003e on your n8n webhook endpoint with \u003cstrong\u003eraw body capture\u003c\/strong\u003e enabled.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eEnforces per-IP sliding-window rate limits\u003c\/strong\u003e and immediately returns \u003cstrong\u003eHTTP 429\u003c\/strong\u003e when a sender exceeds the threshold.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eVerifies HMAC signatures (HMAC-SHA256)\u003c\/strong\u003e using a configured request header and a \u003cstrong\u003etiming-safe comparison\u003c\/strong\u003e against the raw payload.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eBlocks replay attacks\u003c\/strong\u003e by validating request timestamps (with allowed clock skew) and rejecting previously seen \u003cstrong\u003esignature+timestamp\u003c\/strong\u003e pairs.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eValidates required fields\u003c\/strong\u003e and applies a \u003cstrong\u003emaximum payload size\u003c\/strong\u003e check before processing.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eOptionally allows only approved IPs\u003c\/strong\u003e using a \u003cstrong\u003eCIDR-aware allow-list\u003c\/strong\u003e, returning the appropriate verdict status code.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eWrites structured audit logs\u003c\/strong\u003e for every request to a configurable \u003cstrong\u003eHTTP endpoint\u003c\/strong\u003e, including verdict details and a \u003cstrong\u003etruncated hash\u003c\/strong\u003e of the body.\u003c\/li\u003e\n  \u003cli\u003eIf the request fails, it tracks repeated failures per IP and \u003cstrong\u003eposts an alert to Slack\u003c\/strong\u003e once a threshold is exceeded; successful requests run your placeholder \u003cstrong\u003eBusiness Logic\u003c\/strong\u003e step and return \u003cstrong\u003e200\u003c\/strong\u003e.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eSaaS operators protecting webhook endpoints from abuse, replay attempts, and request floods.\u003c\/li\u003e\n  \u003cli\u003eAutomation engineers integrating third-party services that require signed webhook verification.\u003c\/li\u003e\n  \u003cli\u003eTeams needing auditability for inbound webhook security events via an HTTP logging endpoint.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003en8n nodes: \u003cstrong\u003ewebhook\u003c\/strong\u003e, \u003cstrong\u003ecode\u003c\/strong\u003e, \u003cstrong\u003eif\u003c\/strong\u003e, \u003cstrong\u003eset\u003c\/strong\u003e, \u003cstrong\u003eno op\u003c\/strong\u003e, and \u003cstrong\u003eslack\u003c\/strong\u003e.\u003c\/li\u003e\n  \u003cli\u003eCore protections: \u003cstrong\u003erate limiting\u003c\/strong\u003e, \u003cstrong\u003eHMAC-SHA256\u003c\/strong\u003e verification, \u003cstrong\u003etimestamp validation\u003c\/strong\u003e, \u003cstrong\u003ereplay prevention\u003c\/strong\u003e, payload \u003cstrong\u003efield checks\u003c\/strong\u003e and \u003cstrong\u003esize limits\u003c\/strong\u003e, and \u003cstrong\u003eCIDR IP allow-listing\u003c\/strong\u003e.\u003c\/li\u003e\n  \u003cli\u003eSecurity monitoring: \u003cstrong\u003eSlack alerts\u003c\/strong\u003e after repeated failure thresholds.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":46154069737651,"sku":"N8N-20060","price":55.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/dMQC8osrZlTw_IjtbgS5m_ZGhMPuTO.png?v=1790933329","url":"https:\/\/buyflowscripts.com\/products\/secure-n8n-inbound-webhook-with-hmac-rate-limits-slack","provider":"N8N Commerce","version":"1.0","type":"link"}