--- id: crypto-hmac_sha256 name: Crypto.hmac_sha256 category: crypto kind: namespace-method tokens: Crypto.hmac_sha256 sig: Crypto.hmac_sha256(key, msg) -> string tip: Sign a message with a shared secret key. order: 2 ns: Crypto member: hmac_sha256 --- Computes HMAC-SHA256 over msg under the secret key (RFC 2104) and returns the 64-character lowercase hex tag. Unlike a bare hash, a MAC cannot be recomputed without the key, so it authenticates the message: attach the tag to a save file or a network packet, and a receiver who shares the key can tell whether the payload was altered or forged. To check the tag on the other side, pass it to Crypto.verify_hmac rather than comparing hex with ==. Parameters: - `key` — the shared secret; keep it out of the shipped client where you can - `msg` — the payload being signed ```ludic program SignSave { entry { let key = "s3cret" let payload = "score=9001;level=12" let mac = Crypto.hmac_sha256(key, payload) print(mac) } } ```