> ## Documentation Index
> Fetch the complete documentation index at: https://docs.jesta.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security model

> Per-endpoint secrets, signed callbacks, and the gated installer.

Two things have to be right for Thumper to be trustworthy: a trigger must be
**unforgeable** (the `POST /api/trigger` endpoint is reachable by every endpoint,
so it's effectively public), and the installer must not **leak** the enroll token
to anyone who hasn't been authorized to deploy.

## Unique per-endpoint secrets

Each deployment carries its own `hmac_secret`, minted server-side and handed
*only* to that endpoint's agent - via `GET /api/agent/deployments`. The secret is:

* **Never returned by the UI API.** No dashboard call exposes it.
* **Never written into the planted file.** The bait on disk contains no secret
  material.

So a secret leaked from one box can't forge another box's triggers - each
deployment can only sign for itself.

## Signed callbacks

The agent signs the **exact** request body and sends
`X-Thumper-Signature: sha256=<hmac>`. On the server:

1. It looks up the deployment named in the body.
2. It recomputes the HMAC over the **raw bytes** of the request with that
   deployment's secret.
3. It compares the two in **constant time**.

An unknown deployment and a bad signature both return `401` - there's no oracle
that distinguishes them. This is verified end-to-end, including that one
endpoint's secret cannot forge another's trigger.

## Gated installer

`GET /api/install.sh` embeds the enroll token, so it must not be fetchable
anonymously. It's gated behind an admin install token: the server-generated
deploy command carries that token, and the installer is only served to a request
that presents it. The enroll token reaches endpoints through the deploy command
your fleet tooling runs - never from an open, unauthenticated download.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.