-
SubtleCrypto でローカル計算 — メッセージとシークレットがデバイスの外に出ることはありません。セキュアコンテキスト (https または localhost) が必要です。
HMAC-SHA-256 用の Python `hmac.compare_digest` 検証器を書いてください。シークレットは環境変数から読み込むこと — 絶対にハードコードしない。テストベクトル — メッセージ: ``、期待される MAC (hex): ``。
機能の説明
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
ジェネレーターは、メッセージとシークレットからキー付きハッシュメッセージ認証コード(HMAC)を計算します — SHA-1、SHA-256、SHA-384、SHA-512 に対応。HMAC は Stripe や GitHub がウェブフックに署名する仕組みであり、ペイロードが本当に彼らから来たものだと検証できます。ハッシュ計算はすべてブラウザの Web Crypto API を使用 — メッセージもシークレットも端末の外に出ません。使い方
- Message を入力します(署名したいペイロード)。
- Secret を入力します(共有署名鍵)。
- Algorithm を選びます(SHA-256 が現代のデフォルト)。
- 結果の hex ダイジェストをコピーします。
例
- ウェブフックの検証: 生のリクエストボディをウェブフックシークレットで
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
-SHA-256 計算し、X-Signatureヘッダーと(定数時間で)比較します。 - テストベクトル(RFC 4231): 鍵 =
0x0bを 20 バイト、メッセージ ="Hi There"、SHA-256 →b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7。
補足事項
- 新規システムには SHA-256 以上を使ってください。 SHA-1 の
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
はレガシー互換のためだけに含まれています。 - ダイジェストはサーバー側で定数時間比較して、タイミング攻撃を避けてください。
- プライベート: 計算は
crypto.subtleにより 100% クライアントサイド — 実際のシークレットにも安全です。 - 関連ツール:
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
(SHA)、JWTJWTA compact, URL-safe token that carries claims (like identity or expiry) between two parties, signed to prevent tampering.Learn more
Decoder、Base64Base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
。