Skip to main content
Two things have to be right for Thumper to be trustworthy: a trigger must be unforgeable (the POST /api/trigger endpoint is reachable by every endpoint, so it’s effectively public), and the installer must not leak the enroll token to anyone who hasn’t been authorized to deploy.

Unique per-endpoint secrets

Each deployment carries its own hmac_secret, minted server-side and handed only to that endpoint’s agent - via GET /api/agent/deployments. The secret is:
  • Never returned by the UI API. No dashboard call exposes it.
  • Never written into the planted file. The bait on disk contains no secret material.
So a secret leaked from one box can’t forge another box’s triggers - each deployment can only sign for itself.

Signed callbacks

The agent signs the exact request body and sends X-Thumper-Signature: sha256=<hmac>. On the server:
  1. It looks up the deployment named in the body.
  2. It recomputes the HMAC over the raw bytes of the request with that deployment’s secret.
  3. It compares the two in constant time.
An unknown deployment and a bad signature both return 401 - there’s no oracle that distinguishes them. This is verified end-to-end, including that one endpoint’s secret cannot forge another’s trigger.

Gated installer

GET /api/install.sh embeds the enroll token, so it must not be fetchable anonymously. It’s gated behind an admin install token: the server-generated deploy command carries that token, and the installer is only served to a request that presents it. The enroll token reaches endpoints through the deploy command your fleet tooling runs - never from an open, unauthenticated download.