HMAC Verify
Verify an HMAC signature. Mismatch fails the block.
Type
crypto.hmac.verifyFolder
basic/cryptoChannels
Any
Pipe
Value
Scope
Any
HMAC Verify recomputes the HMAC of Value with Secret and compares it to Signature. The compare is timing-safe. A mismatch does not continue on the success outlet.
Configure
| Setting | Description |
|---|---|
| Value | Signed body or text (required) |
| Secret | Shared secret. Prefer a workspace env key (required) |
| Signature | Expected signature, usually a request header (required) |
| Algorithm | Must match how the signature was created |
| Encoding | Must match how the signature was encoded |
Handles
| Handle | Role |
|---|---|
| In (target) | Incoming connection |
| Out (source) | Continues only when the signature matches |
| Error | Catchable failures: missing secret (MISSING_VALUE) or signature mismatch (HMAC_INVALID) |
Connect Branch errors to Error to split those codes.
Pipe schema
On success the pipe is an object: valid is yes. Catch errors with a block Error outlet or Try.
Use case
- Check a partner webhook posted to an HTTP Server before you process the body.
- Confirm an outbound request you signed with HMAC Create.