Vettero

Crypto

HMAC signatures and JSON web tokens for webhook and API auth.

Crypto blocks sit in the builder palette under Basic → Crypto. They work on any workflow channel. Shared graph rules are on Workflows.

Use these when a partner webhook needs a signature check, or when you mint or check a bearer token. Put secrets in workspace env keys (variable mode), not as long-lived literals on the canvas.

Invalid HMAC or JWT checks are catchable errors (MISSING_VALUE, HMAC_INVALID, JWT_INVALID, JWT_MALFORMED). Catch them with a block Error outlet or Try. Connect Branch errors to Error to split those codes.

UseBlock
Sign a webhook body or requestHMAC Create
Check an inbound signatureHMAC Verify
Mint a bearer tokenJWT Sign
Trust an inbound JWTJWT Verify
Inspect claims without checking the signatureJWT Decode

5

HMAC Create
HMAC-sign a value with a secret. Hex, Base64, or Base64 URL.
HMAC Verify
Check an HMAC signature. Mismatch fails the block.
JWT Sign
Sign a JSON web token with a secret or PEM private key.
JWT Verify
Verify a JWT signature and claims. Invalid tokens fail the block.
JWT Decode
Read JWT claims without checking the signature. Untrusted.
Copyright © 2026