# Bundle Fingerprint

WHost's web panel sends an `X-WHost-Bundle-Fingerprint` header so the
browser bundle and the agent stay in lock-step. **HMAC-authenticated
requests are exempt** — SDKs and third-party integrations should
**never** send this header and never need to know the agent's current
fingerprint.

The agent skips the fingerprint check when `X-WHost-Key` is non-empty,
then applies the request's authentication and authorization checks. The
key header alone does not authenticate a request. Without a session
cookie, an authorized `GET /api/v1/accounts` request with valid HMAC succeeds even if the
fingerprint header is missing or incorrect; an invalid HMAC signature
returns `401 AUTH_FAILED` in either case.

EventSource streams and OAuth callbacks are exempt only when the
normalized, decoded request path matches a complete permitted route.
Appending a newline, carriage return, or tab does not preserve that
route exemption. These exemptions affect only the fingerprint check;
the route's authentication requirements still apply.

The exemption is enforced agent-side and covered by the agent's
integration tests.

---
