Skip to main content
Glama

Tanod Util

utilpeek: sign or verify an HMAC (webhook signatures)

hmac_sign_verify
Read-onlyIdempotent

utilpeek: Sign or verify an HMAC, including GitHub, Stripe and Slack webhook signatures. Returns the HMAC of a message under a shared key (sign), or whether a signature matches it in constant time (verify); handles GitHub (sha256= prefix accepted), Stripe v1 (of {t}.{raw body}) and Slack v0 (of v0:{timestamp}:{raw body}) webhook signatures. Input: mode, message, key, optional key_encoding, algorithm, output and, for verify, signature. Malformed hex or base64, a sha*= prefix naming another algorithm, or verify without a signature is a 422 (not charged). Other prefixes (v0=, v1=) are not stripped. sha1 is for legacy webhooks only. The key and message are never echoed. Typically under 0.1 s. Price: USD 0.001. Free: 10 utilpeek calls per IP per UTC day. Tanod does not log or store the submitted text; it is processed in memory for this answer. Docs: https://tanod.dev/learn/verify-webhook-signature-hmac-api.html

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
keyYesThe shared secret (at most 1 KiB), read as `key_encoding`. Never echoed or logged.
modeYessign (compute the HMAC) or verify (check `signature`).
outputNoSignature encoding: hex (default) or base64.hex
messageYesThe signed payload exactly as received (e.g. the raw webhook body), as text; at most 64 KiB as UTF-8.
algorithmNosha256 (default), sha512, or sha1 (legacy webhooks only).sha256
signatureNoverify only: the signature to check, in `output` encoding. A `sha256=` style prefix (GitHub's X-Hub-Signature-256) is stripped when it names `algorithm`.
key_encodingNoutf8 (default), hex or base64 (standard alphabet).utf8

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
errorNoOnly on an error result: an object {code, message}, or the reason string of an x402 PaymentRequired object.
validNo
outputNo
algorithmNo
signatureNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "properties": {
      +    "algorithm": {
      +      "enum": [
      +        "sha256",
      +        "sha512",
      +        "sha1",
      +        null
      +      ],
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "error": {
      +      "description": "Only on an error result: an object {code, message}, or the reason string of an x402 PaymentRequired object."
      +    },
      +    "output": {
      +      "enum": [
      +        "hex",
      +        "base64",
      +        null
      +      ],
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "signature": {
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "valid": {
      +      "type": [
      +        "boolean",
      +        "null"
      +      ]
      +    }
      +  },
      +  "type": "object"
      +}
  2. First observed

TDQS

Score is being calculated.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources