-
Dikira secara setempat melalui SubtleCrypto — mesej dan rahsia anda tidak pernah keluar dari peranti anda. Memerlukan konteks selamat (https atau localhost).
Write a Python `hmac.compare_digest` verifier for HMAC-SHA-256. Read the secret from an environment variable - never hardcode it. Test vector - message: ``, expected MAC (hex): ``.
(Documentation in English)
What it does
The
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
Generator computes a keyed-hash message authentication code (HMAC) for a message and a secret, using SHA-1, SHA-256, SHA-384, or SHA-512. HMAC is how services like Stripe and GitHub sign webhooks so you can verify a payload genuinely came from them. AllhashinghashingA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
uses the browser’s Web Crypto API - your message and secret never leave your device.How to use it
- Enter the Message (the payload you want to sign).
- Enter the Secret (the shared signing key).
- Pick the Algorithm (SHA-256 is the modern default).
- Copy the resulting hex digest.
Examples
- Verify a webhook: compute
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
-SHA-256 of the raw request body with your webhook secret, then compare (constant-time) to theX-Signatureheader. - Test vector (RFC 4231): key = 20 bytes of
0x0b, message ="Hi There", SHA-256 →b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7.
Good to know
- Use SHA-256 or stronger for new systems; SHA-1
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
is included for legacy compatibility only. - Compare digests in constant time server-side to avoid timing attacks.
- Private: computation is 100% client-side via
crypto.subtle- safe for real secrets. - Related tools:
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
(SHA),JWTJWTA compact, URL-safe token that carries claims (like identity or expiry) between two parties, signed to prevent tampering.Learn more
Decoder,Base64Base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
.