-
Calculado localmente con SubtleCrypto: tu mensaje y tu secreto nunca salen de tu dispositivo. Requiere un contexto seguro (https o localhost).
Escribe un verificador en Python con `hmac.compare_digest` para HMAC-SHA-256. Lee el secreto desde una variable de entorno; nunca lo incrustes en el código. Vector de prueba — mensaje: ``, MAC esperado (hex): ``.
Qué hace
El generador de
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
calcula un código de autenticación de mensajes con clave (HMAC) para un mensaje y un secreto, usando SHA-1, SHA-256, SHA-384 o SHA-512. HMAC es el mecanismo con el que servicios como Stripe y GitHub firman webhooks para que puedas verificar que un payload proviene genuinamente de ellos. Todo elhashinghashingA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
usa la Web Crypto API del navegador — tu mensaje y tu secreto nunca salen de tu dispositivo.Cómo usarlo
- Introduce el Message (el payload que quieres firmar).
- Introduce el Secret (la clave de firma compartida).
- Elige el Algorithm (SHA-256 es el valor moderno por defecto).
- Copia el digest hex resultante.
Ejemplos
- Verificar un webhook: calcula
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
-SHA-256 del cuerpo bruto de la petición con tu secreto de webhook y compáralo (en tiempo constante) con la cabeceraX-Signature. - Vector de prueba (RFC 4231): clave = 20 bytes de
0x0b, mensaje ="Hi There", SHA-256 →b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7.
Bueno saber
- Usa SHA-256 o superior en sistemas nuevos; el
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
de SHA-1 se incluye solo por compatibilidad con sistemas heredados. - Compara los digests en tiempo constante en el servidor para evitar ataques de temporización.
- Privado: el cálculo es 100 % en el cliente vía
crypto.subtle— seguro para secretos reales. - Herramientas relacionadas:
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
(SHA),JWTJWTA compact, URL-safe token that carries claims (like identity or expiry) between two parties, signed to prevent tampering.Learn more
Decoder,Base64Base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
.