POST /v1/core/hmac-sign

HMAC signature

The signature scheme webhooks use, so you can check what a provider sent you actually came from them.

Sign a message with a secret now No key, no code — 1 credit either way.

curl -X POST "$DOATHING_API/v1/core/hmac-sign" \
  -H "x-api-key: $DOATHING_KEY" \
  -H "content-type: application/json" \
  -d '{"text": "payload", "key": "your-webhook-secret"}'

The signature scheme webhooks use, so you can check what a provider sent you actually came from them.

Compute an HMAC over a message with a caller-supplied key, in hex or base64, over any hashlib digest.

Input

Send either a text string or a file object. A file is decoded as UTF-8 and must be one of text/plain, text/markdown, text/html, text/csv.

Response

The result carries your remaining balance alongside it, so you can track spend without a second call.

{
  "signature": "8f1e…",
  "digest": "sha256",
  "encoding": "hex",
  "request_id": "37f01edb-0163-42a1-ac51-0acaef979800",
  "credits_remaining": 96
}

Cost

1 credit per call, whether it is run from the site or from the API — the credential differs, the price does not. A new account starts with 20 credits.

A rejected request still costs a credit: the authorizer decrements before the tool validates. A call rejected for a missing or invalid key is free.

Parameters

Generated from the endpoint’s own validation, so this is exactly what it accepts. A body field goes at the top level; an option goes inside options.

NameInTypeDefaultNotes
key *bodystringThe shared secret. Never logged, never echoed back.
digestoptionsstring"sha256"sha256, sha1, sha384, sha512 or md5. one of sha256, sha1, sha384, sha512, md5
encodingoptionsstring"hex"hex or base64. one of hex, base64