The key stays in this page. Nothing is sent anywhere — but a production signing key is still worth being careful with.

Good to know

  • An HMAC is a hash of the message and a shared secret together. Anyone holding the key can produce it and check it; anyone without it can do neither — which is what makes it a signature rather than a checksum.
  • It is not the same as hashing the key and the message glued together. That construction can be extended by someone who never saw the key; HMAC's two nested passes are what close that hole.
  • When your own code checks an HMAC, compare the two values in constant time. A plain equality check leaks how much of the signature was right through how long it took to say no.
  • The signing is done by the browser's own cryptography, in this page. Neither the message nor the key is sent to the server or stored anywhere.
30 views
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.