# Sha256 hmac

**URL:** <https://community.make.com/t/sha256-hmac/50966>\
**Category:** Questions\
**Tags:** api\
**Created:** [August 14, 2024, 2:30pm UTC](https://community.make.com/t/sha256-hmac/50966 "2024-08-14T14:30:21Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![cmoosbrugger](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@cmoosbrugger](https://community.make.com/u/cmoosbrugger)\
**Post date:** [August 14, 2024, 2:30pm UTC](https://community.make.com/t/sha256-hmac/50966/1 "2024-08-14T14:30:21Z")

</div>

Hi,

we are connecting to a marketplace using an API and they require each request being signed by a SHA-256 HMAC in base64 encoding. This HMAC is generated by concatenating the request information together, separated by newline characters, and generating a SHA-256 HMAC from the resulting string and your `Secret Key` .

the function for the signature in php looks like following

```auto
<?php

$method = "POST";
$uri = "https://sellerapi.kaufland.com/v2/units/";
$body = "";
$timestamp = 1411055926; // Example timestamp
$secretKey = "a7d0cb1da1ddbc86c96ee5fedd341b7d8ebfbb2f5c83cfe0909f4e57f05dd508";

// Get the concatenated string
$string = implode("\n", [
    $method,
    $uri,
    $body,
    $timestamp,
]);

// Generate the HMAC signature
$hmac = hash_hmac('sha256', $string, $secretKey);

// Print the concatenated string and HMAC signature with a line break
print("HMAC signature:\n$hmac\n");

?>

```

with the SHA256 function in make I did not get the correct signature value.

the output should be following

```auto
HMAC signature: 407520bb32bd4b896a9e11a863091b3b815a116bf474a0f7d8ef8e8396fbe5b0

```

but it is

```auto
HMAC signature: 64ac1594393483633bcde0720dc5f9e61dcc045722794d0ba71066b9a7feb69e

```

the variable in make i try to set with following function:

```auto
{{sha256("POST https://sellerapi.kaufland.com/v2/units/ 1411055926"; ; "a7d0cb1da1ddbc86c96ee5fedd341b7d8ebfbb2f5c83cfe0909f4e57f05dd508")}}

```

thanks.  
Christoph

---

<div class="post-metadata">

**Author:** ![ImMichaelCannon](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/immichaelcannon/32/48674_2.png) [@ImMichaelCannon](https://community.make.com/u/ImMichaelCannon)\
**Post date:** [August 15, 2024, 2:42am UTC](https://community.make.com/t/sha256-hmac/50966/2 "2024-08-15T02:42:55Z")

</div>

Hiya @cmoosbrugger; such fun being authenticated…

1. I don’t see the newlines “\n” in your `sha256` string.
2. I think you’re missing `base64` in your `sha256` call as the second parameter per [https://www.make.com/en/help/functions/string-functions#sha256--text---encoding----key----key-encoding--](https://www.make.com/en/help/functions/string-functions#sha256--text---encoding----key----key-encoding--).
3. Though `$body` is blank, there should be a newline for it.

---

<div class="post-metadata">

**Author:** ![cmoosbrugger](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@cmoosbrugger](https://community.make.com/u/cmoosbrugger)\
**Post date:** [August 15, 2024, 7:21am UTC](https://community.make.com/t/sha256-hmac/50966/3 "2024-08-15T07:21:57Z")

</div>

hi,

thanks for your input.

when in the functions file I also print the string before hashing it does not show newlines.

```auto
// Print the concatenated string and HMAC signature with a line break
print("Concatenated string:\n$string\n\n");
print("HMAC signature:\n$hmac\n");

```

the output of those two lines is following:

```auto
Concatenated string: POST https://sellerapi.kaufland.com/v2/units/ 1411055926 HMAC signature: 407520bb32bd4b896a9e11a863091b3b815a116bf474a0f7d8ef8e8396fbe5b0

```

even the empty body string is not there. this is why I was trying it this way.

next question for me would be on how to put new lines into the SHA256 make function? Can I just put there “\n” snippets?

regarding the missing base64 encoding do you mean the encoding for the teyt or the key?

thanks!

---

<div class="post-metadata">

**Author:** ![ImMichaelCannon](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/immichaelcannon/32/48674_2.png) [@ImMichaelCannon](https://community.make.com/u/ImMichaelCannon)\
**Post date:** [August 16, 2024, 3:37am UTC](https://community.make.com/t/sha256-hmac/50966/4 "2024-08-16T03:37:52Z")

</div>

I created a scenario, find attached below, to test out things and found that we should not request `base64` as part of the `sha256` request, besides building up the `$string` more cleanly.

 ![Screenshot 2024-08-16 at 11.29.51](https://europe1.discourse-cdn.com/flex013/uploads/make/original/3X/7/3/738c8a164d90a71d20a22beb6e2e95ae55e470c7.png)

I initiated my variables and then brought them together as an array, which I think joined.

 ![Screenshot 2024-08-16 at 11.34.13](https://europe1.discourse-cdn.com/flex013/uploads/make/original/3X/6/7/676ebe82368c4e0b633736e83a5d401431992171.png)

Create the `hash_hmac`.

![Screenshot 2024-08-16 at 11.34.20](https://europe1.discourse-cdn.com/flex013/uploads/make/original/3X/d/7/d7da1be1ce74322a9aadfc0baab78d7e69453215.png)

[blueprint (1).json](https://community.make.com/uploads/short-url/xMwEJvWxppiFlxESuIrZAetkHos.json) (12.1 KB)

Good luck!

---

<div class="post-metadata">

**Author:** ![cmoosbrugger](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@cmoosbrugger](https://community.make.com/u/cmoosbrugger)\
**Post date:** [August 16, 2024, 8:46am UTC](https://community.make.com/t/sha256-hmac/50966/5 "2024-08-16T08:46:18Z")

</div>

Awesome, this did the trick. Even though the final http request to the platform did not work right away.

as the platform documentation was not clear it was trial and error and finally I found out that when creating the signature, the full request URL (including the query params) must be added not only the base URL.

which is kind of weird but at least I got it to work now.

many thanks!

---

<div class="post-metadata">

**Author:** ![ImMichaelCannon](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/immichaelcannon/32/48674_2.png) [@ImMichaelCannon](https://community.make.com/u/ImMichaelCannon)\
**Post date:** [August 22, 2024, 8:58am UTC](https://community.make.com/t/sha256-hmac/50966/6 "2024-08-22T08:58:16Z")

</div>

Congratulations @cmoosbrugger for the win. And yeah, I’ve found that experimenting with stuff is how I’ll get it solved, even finding undocumented things that work.

---

<div class="post-metadata">

**Author:** ![Make\_Bot](https://dub1.discourse-cdn.com/flex013/user_avatar/community.make.com/make_bot/32/14661_2.png) [@Make\_Bot](https://community.make.com/u/Make_Bot)\
**Post date:** [August 30, 2024, 8:49am UTC](https://community.make.com/t/sha256-hmac/50966/7 "2024-08-30T08:49:04Z")

</div>


