flippercloud/flipper · error · ArgumentError

secret should be a string

Error message

secret should be a string

What it means

Error "secret should be a string" thrown in flippercloud/flipper.

Source

Thrown at lib/flipper/cloud/message_verifier.rb:21

module Flipper
  module Cloud
    class MessageVerifier
      class InvalidSignature < StandardError; end

      DEFAULT_VERSION = "v1"

      def self.header(signature, timestamp, version = DEFAULT_VERSION)
        raise ArgumentError, "timestamp should be an instance of Time" unless timestamp.is_a?(Time)
        raise ArgumentError, "signature should be a string" unless signature.is_a?(String)
        "t=#{timestamp.to_i},#{version}=#{signature}"
      end

      def initialize(secret:, version: DEFAULT_VERSION)
        @secret = secret
        @version = version || DEFAULT_VERSION

        raise ArgumentError, "secret should be a string" unless @secret.is_a?(String)
        raise ArgumentError, "secret should not be empty" if @secret.empty?
        raise ArgumentError, "version should be a string" unless @version.is_a?(String)
      end

      def generate(payload, timestamp)
        raise ArgumentError, "timestamp should be an instance of Time" unless timestamp.is_a?(Time)
        raise ArgumentError, "payload should be a string" unless payload.is_a?(String)

        OpenSSL::HMAC.hexdigest(OpenSSL::Digest.new("sha256"), @secret, "#{timestamp.to_i}.#{payload}")
      end

      def header(signature, timestamp)
        self.class.header(signature, timestamp, @version)
      end

      # Public: Verifies the signature header for a given payload.
      #
      # Raises a InvalidSignature in the following cases:

View on GitHub (pinned to 1f86de3ec9)

Solutions

  1. Provide the webhook secret as a String, e.g. ENV['FLIPPER_CLOUD_WEBHOOK_SECRET']
  2. Check that the configured secret is not being passed as a Symbol or other object
  3. Load the secret from your credentials store as a plain string before constructing the verifier

When it happens

Trigger: Thrown at lib/flipper/cloud/message_verifier.rb:21 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of flippercloud/flipper@1f86de3ec9 (2026-08-23). Data as JSON: /api/errors/9010a581cb6f10f4. Report an issue: GitHub.