Security · Concept

HMAC signatures

A code computed from a message and a shared secret key and sent along with the message, so the receiver can prove it came from someone who knows the secret and was not changed on the way.

Crypto basics · updated

How it works

HMAC (hash-based message authentication code) mixes a secret key into a hash function such as SHA-256. The sender computes HMAC-SHA256 over the exact bytes of a message and sends the result as a signature; the receiver, who holds the same secret, recomputes it and compares. Anyone can read the message, but without the secret nobody can produce a matching signature, and changing a single byte breaks it.

Webhooks are the everyday use. Stripe sends a Stripe-Signature header carrying a signature over a timestamp and the request body. Razorpay sends X-Razorpay-Signature on webhooks, and its checkout returns a signature over the order and payment ids that your server must check before marking an order paid. GitHub (X-Hub-Signature-256) and Shopify work the same way, and JSON Web Tokens signed with HS256 use HMAC too.

Verify against the raw request body before any JSON parsing changes it, compare signatures with a constant-time function so timing leaks nothing, and reject old timestamps to stop replayed requests. HMAC proves who sent a message but does not hide it; that is the job of encryption.

HMAC signatures vs the alternatives

More in Security

Crypto basics

All 20 Security terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.