Bundle Fingerprint

Updated Oct 3, 2026 Markdown

WHost's web panel sends an X-WHost-Bundle-Fingerprint header so the browser bundle and the agent stay in lock-step. HMAC-authenticated requests are exempt — SDKs and third-party integrations should never send this header and never need to know the agent's current fingerprint.

The agent skips the fingerprint check when X-WHost-Key is non-empty, then applies the request's authentication and authorization checks. The key header alone does not authenticate a request. Without a session cookie, an authorized GET /api/v1/accounts request with valid HMAC succeeds even if the fingerprint header is missing or incorrect; an invalid HMAC signature returns 401 AUTH_FAILED in either case.

EventSource streams and OAuth callbacks are exempt only when the normalized, decoded request path matches a complete permitted route. Appending a newline, carriage return, or tab does not preserve that route exemption. These exemptions affect only the fingerprint check; the route's authentication requirements still apply.

The exemption is enforced agent-side and covered by the agent's integration tests.

Still Need Help?

Our support team is here around the clock for anything you can't find above.