How can I make sure that an image is actually from my correct user?
Your application’s backend must authenticate the user and authorize the upload. Keep the Transloadit Auth Secret on that trusted backend. Derive permitted instructions from the authenticated session; blindly signing a browser-supplied user ID does not verify it.
Signature Authentication protects the exact serialized params string. For ordinary signed requests, changing params.fields after signing invalidates the signature. It does not sign separate multipart fields or uploaded file bytes. A later unsigned multipart field can replace a same-named signed field in the merged Assembly fields, so signing params.fields.user_id does not make the final fields.user_id trustworthy.
Enable Signature Authentication for your Workspace when accepting signed browser requests. Include a short-lived auth.expires and return the original serialized params with its signature. Expiration limits the reuse window; it is not a single-use guarantee. Assembly creation can reuse identical signed params before expiry, including params with a nonce. A copied request does not prove that its sender is still logged in. Valid Bearer authentication satisfies the signature requirement without checking a supplied signature; protect Bearer tokens according to their scope.
For an association controlled by your application, create the Assembly from your trusted backend and record its returned assembly_id with the authenticated user. Follow the Resumable Uploads guide to let the client upload files to that existing Assembly, and keep its upload access private. This is a different integration from Uppy’s Transloadit plugin, which creates the Assembly from the browser using assemblyOptions.
Before granting access to results, check the Assembly Status against your app-owned record. For Webhooks, first verify the delivery’s signature, then check its Assembly ID against that record. Do not derive ownership from returned fields or an Assembly ID claimed by a client. This records the upload your application authorized; it does not establish who created the image or prove the contents of the uploaded bytes.