What is an algorithm or formula between X-Request-Id and X-Request-Sign headers?

Topic summary

A developer is working on validating incoming requests to a custom Shopify app with a proxy endpoint. They initially tried to use the x-request-id and x-request-sign headers to verify request authenticity.

Resolution:

  • Another user clarified that signature validation should use URL query parameters, not headers
  • The official Shopify documentation on calculating digital signatures for app proxies was provided as the solution
  • The original poster confirmed this resolved their issue

Follow-up question:
A third user asked how to access the x-request-id header within the app proxy, which remains unanswered.

The discussion appears resolved for the original question, though the follow-up query about header access is still open.

Summarized with AI on November 11. AI used: claude-sonnet-4-5-20250929.

BorisD,

I did miss it :sweat_smile:

thanks a lot!