A worked example, rendered from real sample data. Sign in to run the tool on your own input.
message content here
---
a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6a7b8c9d0e
---
secret_key_dataHMAC Verification
═════════════════
Message: message content here
Expected HMAC: a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6a7b8c9d0e
Key Analysis:
Key Length: 15 bytes
Algorithm: HMAC-SHA256
Verification:
Status: ✗ INVALID
Computed: a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6
Recommendations:
- Use constant-time comparison to prevent timing attacks
- Rotate HMAC keys regularly
- Use HMAC-SHA256 or stronger
Verify HMAC-SHA256 signatures with constant-time comparison analysis. Part of the DevTools Surf developer suite. Browse more tools in the Security / Crypto collection.