Crypto
HMAC signatures and JSON web tokens for webhook and API auth.
Crypto blocks sit in the builder palette under Basic → Crypto. They work on any workflow channel. Shared graph rules are on Workflows.
Use these when a partner webhook needs a signature check, or when you mint or check a bearer token. Put secrets in workspace env keys (variable mode), not as long-lived literals on the canvas.
Invalid HMAC or JWT checks are catchable errors (MISSING_VALUE, HMAC_INVALID, JWT_INVALID, JWT_MALFORMED). Catch them with a block Error outlet or Try. Connect Branch errors to Error to split those codes.
| Use | Block |
|---|---|
| Sign a webhook body or request | HMAC Create |
| Check an inbound signature | HMAC Verify |
| Mint a bearer token | JWT Sign |
| Trust an inbound JWT | JWT Verify |
| Inspect claims without checking the signature | JWT Decode |
5