field Registered
Verified 2026-09-18 · registry updated 2026-08-28

Signature-Input

Defines the components and parameters covered by HTTP Message Signatures.

Use Signature-Input to make the signed request target, fields, creation time, expiry, and key identifier explicit.

httpheadersecurityintegrity

Reference (http)

Signature-Input: sig1=("@method" "@target-uri" "content-digest");created=1720000000;keyid="api-key"

Use Signature-Input to make the signed request target, fields, creation time, expiry, and key identifier explicit.

Common mistakes

  • Leaving freshness or the key identifier out of a replay-sensitive signature.

IANA registry: http-fields/field-names · structured type: Dictionary

Registry reference: RFC 9421, Section 4.1: HTTP Message Signatures

Permalink: https://merginit.com/reference/http/field-signature-input