security
HMAC Verification
Sign messages with a shared secret. Verify integrity by recomputing the HMAC.
signature-
statuspending
// verification log
No operations yet
How It Works
- HMAC = Hash(secret + message)
- Sender computes HMAC, attaches to message
- Receiver recomputes HMAC with shared secret
- Match → message intact; mismatch → tampered
Use Cases
- Webhook signature verification (Stripe, GitHub)
- API request authentication
- JWT signature (HS256)
- Message integrity in transit