How it works
HMAC (hash-based message authentication code) mixes a secret key into a hash function such as SHA-256. The sender computes HMAC-SHA256 over the exact bytes of a message and sends the result as a signature; the receiver, who holds the same secret, recomputes it and compares. Anyone can read the message, but without the secret nobody can produce a matching signature, and changing a single byte breaks it.
Webhooks are the everyday use. Stripe sends a Stripe-Signature header carrying a signature over a timestamp and the request body. Razorpay sends X-Razorpay-Signature on webhooks, and its checkout returns a signature over the order and payment ids that your server must check before marking an order paid. GitHub (X-Hub-Signature-256) and Shopify work the same way, and JSON Web Tokens signed with HS256 use HMAC too.
Verify against the raw request body before any JSON parsing changes it, compare signatures with a constant-time function so timing leaks nothing, and reject old timestamps to stop replayed requests. HMAC proves who sent a message but does not hide it; that is the job of encryption.
HMAC signatures vs the alternatives
Related terms
More in Security
Crypto basics