POST /v1/core/hmac-sign
HMAC signature
The signature scheme webhooks use, so you can check what a provider sent you actually came from them.
Sign a message with a secret now No key, no code — 1 credit either way.
curl -X POST "$DOATHING_API/v1/core/hmac-sign" \
-H "x-api-key: $DOATHING_KEY" \
-H "content-type: application/json" \
-d '{"text": "payload", "key": "your-webhook-secret"}'
The signature scheme webhooks use, so you can check what a provider sent you actually came from them.
Compute an HMAC over a message with a caller-supplied key, in hex or base64, over any hashlib digest.
Input
Send either a text string or a file object. A file is decoded as UTF-8 and must be one of text/plain, text/markdown, text/html, text/csv.
Response
The result carries your remaining balance alongside it, so you can track spend without a second call.
{
"signature": "8f1e…",
"digest": "sha256",
"encoding": "hex",
"request_id": "37f01edb-0163-42a1-ac51-0acaef979800",
"credits_remaining": 96
}
Cost
1 credit per call, whether it is run from the site or from the API — the credential differs, the price does not. A new account starts with 20 credits.
A rejected request still costs a credit: the authorizer decrements before the tool validates. A call rejected for a missing or invalid key is free.
Parameters
Generated from the endpoint’s own validation, so this is exactly what it accepts. A body field goes at the top level; an option goes inside options.
| Name | In | Type | Default | Notes |
|---|---|---|---|---|
| key * | body | string | — | The shared secret. Never logged, never echoed back. |
| digest | options | string | "sha256" | sha256, sha1, sha384, sha512 or md5. one of sha256, sha1, sha384, sha512, md5 |
| encoding | options | string | "hex" | hex or base64. one of hex, base64 |