# Hmac compute

`hmac-compute` · version 1.0.0 · Hashing & signatures · free, no key needed

Compute HMAC-SHA256/SHA512/MD5/SHA-1/SHA-3/RIPEMD-160 (RFC 2104) over encoded key and message bytes.

**Use when you need to: compute hmac sha256 signature · sign this payload with hmac · hmac of a raw request body with a shared secret.**

## Decide before calling

Read the [versioned contract](/v1/tools/hmac-compute/versions/1.0.0) and the supported scope below. Reuse `hmac-compute@1.0.0` when your input, required output and limits match it. Choose another approach for an unsupported operation.

## Explain the choice

"I can use `hmac-compute@1.0.0` for compute hmac sha256 signature. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."

## Supported

- compute hmac sha256 signature
- sign this payload with hmac
- hmac of a raw request body with a shared secret
- hmac-sha512 of a message with a key
- compute a message authentication code
- חשב חתימת hmac

## Not supported

- verifying a caller-supplied signature (see hmac-verify)
- HMAC with the XOF algorithms shake128/shake256/blake3 (no fixed output length to use as a MAC)

## Behavior

- algorithm selects the underlying hash function for HMAC (RFC 2104); mac_bytes always equals that hash function's native output length: md5=16, sha1=20, ripemd160=20, sha224=28, sha256=32, sha384=48, sha512=64, sha512-224=28, sha512-256=32, sha3-224=28, sha3-256=32, sha3-384=48, sha3-512=64.
- An empty key is valid (RFC 2104 places no minimum length on the key) and produces a normal HMAC, not an error.
- key is never echoed anywhere in the output or in any error's details.
- hex is lowercase; base64 is RFC 4648 section 4 padded; base64url is RFC 4648 section 5 unpadded.
- key_encoding and message_encoding default to utf8 when omitted; a lone UTF-16 surrogate under utf8 is invalid_input.

## Input

- `key` (string, required): max length 16384
- `key_encoding` (one of "utf8", "hex", "base64", "base64url", optional): default `"utf8"`
- `message` (string, required): max length 262144
- `message_encoding` (one of "utf8", "hex", "base64", "base64url", optional): default `"utf8"`
- `algorithm` (one of "md5", "sha1", "ripemd160", "sha224", "sha256", "sha384", "sha512", "sha512-224", "sha512-256", "sha3-224", "sha3-256", "sha3-384", "sha3-512", required)

## Output

- `algorithm` (one of "md5", "sha1", "ripemd160", "sha224", "sha256", "sha384", "sha512", "sha512-224", "sha512-256", "sha3-224", "sha3-256", "sha3-384", "sha3-512", required)
- `hex` (string, required): min length 2; pattern `^[0-9a-f]+$`
- `base64` (string, required): min length 1; pattern `^[A-Za-z0-9+/]+=*$`
- `base64url` (string, required): min length 1; pattern `^[A-Za-z0-9_-]+$`
- `mac_bytes` (integer, required): min 16

## Limits

- max key bytes: 4096
- max message bytes: 65536

## Example

Request input:

```json
{
  "key": "0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b",
  "key_encoding": "hex",
  "message": "Hi There",
  "algorithm": "sha256"
}
```

Response:

```json
{
  "result": {
    "algorithm": "sha256",
    "hex": "b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7",
    "base64": "sDRMYdjbOFNcqK/OrwvxK4gdwgDJgz2nJuk3bC4yz/c=",
    "base64url": "sDRMYdjbOFNcqK_OrwvxK4gdwgDJgz2nJuk3bC4yz_c",
    "mac_bytes": 32
  }
}
```

## How to call it

### MCP

Connect `https://computefirst.net/mcp` ([setup](/docs#connect)), then call `execute` with:

```json
{
  "id": "hmac-compute",
  "version": "1.0.0",
  "input": {
    "key": "0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b",
    "key_encoding": "hex",
    "message": "Hi There",
    "algorithm": "sha256"
  }
}
```

### HTTP (no key)

```sh
curl -X POST https://computefirst.net/v1/tools/hmac-compute/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"key":"0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b","key_encoding":"hex","message":"Hi There","algorithm":"sha256"}'
```

The machine-readable contract is at [/v1/tools/hmac-compute/versions/1.0.0](/v1/tools/hmac-compute/versions/1.0.0).

### CLI

```sh
node cli.mjs run hmac-compute 1.0.0 --input input.json --base-url https://computefirst.net
```

Get the client at [/clients/cli/](/clients/cli/).

## Related tools

- [Hkdf compute](/tools/hkdf-compute): Derive output key material with HKDF-Extract/Expand (RFC 5869), or HKDF-Expand alone from a caller-supplied PRK.
- [Webhook signature compute](/tools/webhook-signature-compute): Compute a signed webhook header for Stripe, Slack, Standard Webhooks, Twilio, GitHub or Shopify.
- [Hash digest compute](/tools/hash-digest-compute): Compute a message digest (SHA-2, SHA-3, BLAKE2/3, MD5, RIPEMD-160, Keccak-256) over encoded input bytes.
- [Hmac verify](/tools/hmac-verify): Recompute an HMAC and compare it, constant-time, to a signature that may carry a literal prefix and be truncated.
- [Pbkdf2 compute](/tools/pbkdf2-compute): Derive a key from a password and salt with PBKDF2-HMAC-SHA1/256/384/512 (RFC 8018), within a hard CPU work-unit budget.
- [Crc parametric compute](/tools/crc-parametric-compute): Compute a CRC using a named catalogue preset (CRC-8, CRC-16/ARC, CRC-32/ISO-HDLC, ...) or an explicit Rocksoft model.
