In more detail
Both sides share the key. The sender computes HMAC(key, message) and sends it with the message; the receiver recomputes it and compares. HMAC-SHA-256 signs API requests and webhooks, and HS256 JWTs use it. Compare the result in constant time.