Bundle Fingerprint
WHost's web panel sends an X-WHost-Bundle-Fingerprint header so the
browser bundle and the agent stay in lock-step. HMAC-authenticated
requests are exempt — SDKs and third-party integrations should
never send this header and never need to know the agent's current
fingerprint.
The agent skips the fingerprint check when X-WHost-Key is non-empty,
then applies the request's authentication and authorization checks. The
key header alone does not authenticate a request. Without a session
cookie, an authorized GET /api/v1/accounts request with valid HMAC succeeds even if the
fingerprint header is missing or incorrect; an invalid HMAC signature
returns 401 AUTH_FAILED in either case.
EventSource streams and OAuth callbacks are exempt only when the normalized, decoded request path matches a complete permitted route. Appending a newline, carriage return, or tab does not preserve that route exemption. These exemptions affect only the fingerprint check; the route's authentication requirements still apply.
The exemption is enforced agent-side and covered by the agent's integration tests.
Our support team is here around the clock for anything you can't find above.