utilpeek: sign or verify an HMAC (webhook signatures)
hmac_sign_verifyutilpeek: Sign or verify an HMAC, including GitHub, Stripe and Slack webhook signatures. Returns the HMAC of a message under a shared key (sign), or whether a signature matches it in constant time (verify); handles GitHub (sha256= prefix accepted), Stripe v1 (of {t}.{raw body}) and Slack v0 (of v0:{timestamp}:{raw body}) webhook signatures. Input: mode, message, key, optional key_encoding, algorithm, output and, for verify, signature. Malformed hex or base64, a sha*= prefix naming another algorithm, or verify without a signature is a 422 (not charged). Other prefixes (v0=, v1=) are not stripped. sha1 is for legacy webhooks only. The key and message are never echoed. Typically under 0.1 s. Price: USD 0.001. Free: 10 utilpeek calls per IP per UTC day. Tanod does not log or store the submitted text; it is processed in memory for this answer. Docs: https://tanod.dev/learn/verify-webhook-signature-hmac-api.html
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| key | Yes | The shared secret (at most 1 KiB), read as `key_encoding`. Never echoed or logged. | |
| mode | Yes | sign (compute the HMAC) or verify (check `signature`). | |
| output | No | Signature encoding: hex (default) or base64. | hex |
| message | Yes | The signed payload exactly as received (e.g. the raw webhook body), as text; at most 64 KiB as UTF-8. | |
| algorithm | No | sha256 (default), sha512, or sha1 (legacy webhooks only). | sha256 |
| signature | No | verify only: the signature to check, in `output` encoding. A `sha256=` style prefix (GitHub's X-Hub-Signature-256) is stripped when it names `algorithm`. | |
| key_encoding | No | utf8 (default), hex or base64 (standard alphabet). | utf8 |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| error | No | Only on an error result: an object {code, message}, or the reason string of an x402 PaymentRequired object. | |
| valid | No | ||
| output | No | ||
| algorithm | No | ||
| signature | No |