flippercloud/flipper · error · ArgumentError

signature should be a string

Error message

signature should be a string

What it means

Error "signature should be a string" thrown in flippercloud/flipper.

Source

Thrown at lib/flipper/cloud/message_verifier.rb:13

require "openssl"
require "digest/sha2"

module Flipper
  module Cloud
    class MessageVerifier
      class InvalidSignature < StandardError; end

      DEFAULT_VERSION = "v1"

      def self.header(signature, timestamp, version = DEFAULT_VERSION)
        raise ArgumentError, "timestamp should be an instance of Time" unless timestamp.is_a?(Time)
        raise ArgumentError, "signature should be a string" unless signature.is_a?(String)
        "t=#{timestamp.to_i},#{version}=#{signature}"
      end

      def initialize(secret:, version: DEFAULT_VERSION)
        @secret = secret
        @version = version || DEFAULT_VERSION

        raise ArgumentError, "secret should be a string" unless @secret.is_a?(String)
        raise ArgumentError, "secret should not be empty" if @secret.empty?
        raise ArgumentError, "version should be a string" unless @version.is_a?(String)
      end

      def generate(payload, timestamp)
        raise ArgumentError, "timestamp should be an instance of Time" unless timestamp.is_a?(Time)
        raise ArgumentError, "payload should be a string" unless payload.is_a?(String)

        OpenSSL::HMAC.hexdigest(OpenSSL::Digest.new("sha256"), @secret, "#{timestamp.to_i}.#{payload}")
      end

View on GitHub (pinned to 1f86de3ec9)

Solutions

  1. Pass the signature header as a String (e.g. request.headers['Flipper-Signature']), not a parsed object
  2. Do not symbolize or cast the signature value before verification
  3. Ensure the signature argument is not nil; a missing header should be handled before calling the verifier

When it happens

Trigger: Thrown at lib/flipper/cloud/message_verifier.rb:13 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of flippercloud/flipper@1f86de3ec9 (2026-08-23). Data as JSON: /api/errors/3b2ea492cc12f1d3. Report an issue: GitHub.