Hmac verify

hmac-verify · version 1.0.0 · Hashing & signatures · free, no key needed

Recompute an HMAC and compare it, constant-time, to a signature that may carry a literal prefix and be truncated.

Use when you need to: verify a github webhook signature · check hmac signature on a request · validate x-hub-signature-256 header.

Decide before calling

Read the versioned contract and the supported scope below. Reuse hmac-verify@1.0.0 when your input, required output and limits match it. Choose another approach for an unsupported operation.

Explain the choice

"I can use hmac-verify@1.0.0 for verify a github webhook signature. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."

Supported

Not supported

Behavior

Input

Output

Limits

Example

Request input:

{
  "key": "0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b",
  "key_encoding": "hex",
  "message": "Hi There",
  "algorithm": "sha256",
  "signature": "b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7"
}

Response:

{
  "result": {
    "valid": true,
    "reason": null,
    "algorithm": "sha256",
    "matched_encoding": "hex"
  }
}

How to call it

MCP

Connect https://computefirst.net/mcp (setup), then call execute with:

{
  "id": "hmac-verify",
  "version": "1.0.0",
  "input": {
    "key": "0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b",
    "key_encoding": "hex",
    "message": "Hi There",
    "algorithm": "sha256",
    "signature": "b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7"
  }
}

HTTP (no key)

curl -X POST https://computefirst.net/v1/tools/hmac-verify/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"key":"0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b","key_encoding":"hex","message":"Hi There","algorithm":"sha256","signature":"b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7"}'

The machine-readable contract is at /v1/tools/hmac-verify/versions/1.0.0.

CLI

node cli.mjs run hmac-verify 1.0.0 --input input.json --base-url https://computefirst.net

Get the client at /clients/cli/.