Oh, and if your HMAC seals over an origin timestamp which your API respects, you've gone and made things even harder.