# @digitalbazaar/http-signature-header

> [![NPM Version](https://img.shields.io/npm/v/http-signature-header.svg)](https://npm.im/http-signature-header) [![Build status](https://img.shields.io/github/workflow/status/digitalbazaar/http-signature-header/Node.js%20CI)](https://github.com/digitalbaza

Latest version **5.0.1** (published 2024-08-08) · BSD-3-Clause license · 0 weekly downloads

## Install

```sh
npm install @digitalbazaar/http-signature-header
pnpm add @digitalbazaar/http-signature-header
yarn add @digitalbazaar/http-signature-header
bun add @digitalbazaar/http-signature-header
```

## Health

**Score 20/100 (F)** — status: abandoned.

Positive: esm support; no vulnerabilities.

Warnings: low downloads; no types.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 5.0.1 |
| Published | 2024-08-08 |
| First published | 2022-01-11 |
| Weekly downloads | 0 |
| License | BSD-3-Clause |
| TypeScript types | none |
| Module format | ESM |
| Node | >=14 |
| Dependencies | 1 |
| Unpacked size | 23.5 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 9 |
| Author | Digital Bazaar, Inc. |
| Maintainers | dlongley, msporny, davidlehn, mattcollier, gannan |

## Links

- npm: https://www.npmjs.com/package/@digitalbazaar/http-signature-header
- Repository: https://github.com/digitalbazaar/http-signature-header
- Homepage: https://github.com/digitalbazaar/http-signature-header#readme
- Issues: https://github.com/digitalbazaar/http-signature-header/issues
- npm.io page: https://npm.io/package/@digitalbazaar/http-signature-header

## Dependencies (1)

- [assert-plus](https://npm.io/package/assert-plus.md) ^1.0.0

## Recent versions

- 5.0.1 (latest) — 2024-08-08
- 5.0.0 — 2022-06-02
- 4.1.0 — 2022-04-14
- 4.0.1 — 2022-01-11
- 4.0.0 — 2022-01-11

## README

# HTTP Signature Header _(http-signature-header)_

[![NPM Version](https://img.shields.io/npm/v/http-signature-header.svg)](https://npm.im/http-signature-header)
[![Build status](https://img.shields.io/github/workflow/status/digitalbazaar/http-signature-header/Node.js%20CI)](https://github.com/digitalbazaar/http-signature-header/actions?query=workflow%3A%22Node.js+CI%22)
[![Coverage status](https://img.shields.io/codecov/c/github/digitalbazaar/http-signature-header)](https://codecov.io/gh/digitalbazaar/http-signature-header)

> A JavaScript library for creating and verifying HTTP Signature headers

## Table of Contents

- [Background](#background)
- [Install](#install)
- [Usage](#usage)
- [Contribute](#contribute)
- [Commercial Support](#commercial-support)
- [License](#license)

## Background

**[HTTP Signatures IETF draft](https://tools.ietf.org/html/draft-cavage-http-signatures)**

## Install

To install locally (for development):

```
git clone https://github.com/digitalbazaar/http-signature-header.git
cd http-signature-header
npm install
```

## Usage

```js
import {
  createAuthzHeader, createSignatureString
} from '@digitalbazaar/http-signature-header';

const requestOptions = {
  url,
  method: 'POST',
  headers
}
const includeHeaders = ['expires', 'host', '(request-target)'];
const plaintext = createSignatureString({includeHeaders, requestOptions});

const data = new TextEncoder().encode(plaintext);
const signature = base64url.encode(await signer.sign({data}));

const Authorization = createAuthzHeader({
  includeHeaders,
  keyId: signer.id,
  signature
});
```

## Contribute

Please follow the existing code style.

PRs accepted.

If editing the Readme, please conform to the
[standard-readme](https://github.com/RichardLitt/standard-readme) specification.

## Commercial Support

Commercial support for this library is available upon request from
Digital Bazaar: support@digitalbazaar.com

## License

[BSD-3-Clause](LICENSE.md) © Digital Bazaar

---
_Source: https://npm.io/package/@digitalbazaar/http-signature-header · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
