-
通过 SubtleCrypto 在本地计算 — 你的消息和密钥绝不会离开你的设备。需要安全上下文(https 或 localhost)。
Write a Python `hmac.compare_digest` verifier for HMAC-SHA-256. Read the secret from an environment variable - never hardcode it. Test vector - message: ``, expected MAC (hex): ``.
功能说明
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
生成器为一条消息和一个密钥计算密钥哈希消息认证码(HMAC),支持 SHA-1、SHA-256、SHA-384 或 SHA-512。HMAC 是 Stripe 和 GitHub 等服务为 Webhook 签名的机制,让你能够验证载荷确实来自它们。所有哈希计算都使用浏览器的 Web Crypto API —— 你的消息和密钥永远不会离开你的设备。使用方法
- 输入 Message(要签名的载荷)。
- 输入 Secret(共享签名密钥)。
- 选择 Algorithm(SHA-256 是现代默认值)。
- 复制生成的 hex 摘要。
示例
- 验证 Webhook: 用你的 Webhook 密钥计算原始请求体的
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
-SHA-256,然后与X-Signature头进行(常数时间)比较。 - 测试向量(RFC 4231): 密钥 = 20 字节的
0x0b,消息 ="Hi There",SHA-256 →b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7。
补充说明
- 新系统请使用 SHA-256 或更强的算法;SHA-1 的
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
仅为兼容旧系统而保留。 - 在服务器端以常数时间比较摘要,以避免时序攻击。
- 隐私: 计算通过
crypto.subtle100% 在客户端完成 —— 对真实密钥也安全。 - 相关工具:
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
(SHA)、JWTJWTA compact, URL-safe token that carries claims (like identity or expiry) between two parties, signed to prevent tampering.Learn more
Decoder、Base64Base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
。