HomeGlossaryHMAC authentication
← All glossary terms
Developer API · Distribution Hub Glossary

HMAC authentication

A message-authentication method that proves a request was signed with a shared secret and has not been silently altered.

A backend computes a keyed cryptographic digest over the provider's specified canonical message. The verifier recomputes it and checks equality securely. Distribution Hub's API uses documented signed requests; clients must follow the exact timestamp, body and signature rules rather than inventing their own string format.

Key facts

  • Request body and timestamp handling must match documentation
  • Never reveal the shared signing secret
  • Use the correct hash and signature encoding
This glossary explains general industry concepts and supported Distribution Hub workflows. Review individual product restrictions, current rates and official API documentation before ordering.