Glossary Security

HMAC

HMAC (hash-based message authentication code) is a hash computed with a secret key, which proves a message came from someone holding the key and was not altered.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

Both sides share the key. The sender computes HMAC(key, message) and sends it with the message; the receiver recomputes it and compares. HMAC-SHA-256 signs API requests and webhooks, and HS256 JWTs use it. Compare the result in constant time.

Try these tools

See also

  • Glossary Hash
    A hash is the fixed-length fingerprint a hash function computes from any input; the same input always gives the same hash.
  • Glossary JWT
    A JWT (JSON Web Token) is a compact, signed token made of three Base64URL parts that carries claims such as who a user is and when the.
  • Guide How Hashing Works
    What a hash function does, the avalanche effect shown with real SHA-256 output, which algorithms are still safe, HMAC.
AdSense Placeholder
Slot: footer_leaderboard