# HMACs
> [HTML Version](hmacs.htm)
_Added May 2018_
Opcode CRYPTOP\_HMAC allows CRYPTO to create HMACs (Hash-based Message Authentication Codes), commonly used for signing web service requests. They combine a hash/digest algorithm (e.g. SHA256) with a cryptographic key (typically pre-shared between sender and receiver) to both verify data integrity of a message and authenticate the sender.
**xcall CRYPTO, CRYPTOP\_HMAC, status, src, decoding, dst, encoding, cflags, cipher, key \{, keybits, cmode, padding, cbsrc\}**
**Parameters**
_src_ and _decoding_
specify the source message and decoding, as with other opcodes.
_dst and encoding _
specify the destination for the output of the function. Typically it is encoded using base64 or hex so as to make it easily insertable into a web document. The destination length is independent of the source length and instead is determined by the hash function—e.g. SHA256 results in 32 bytes raw, 43 for base64, 64 for hex.
_cflags _
used as for the other opcodes
_cipher _
should be set to CRYPTO\_CIPHER\_NA (0)
_key_
as for the CRYPTOP\_ENCODE operation
_keybits _
may be set to 0 if the key is encoded in a text format; otherwise it should specify the number of bytes in a binary-format key.
_mode _
should be set to one of the following to specify the hash function to use (default CRYPTO\_MODE\_SHA1):
| **Symbol** | **Value** | **Description** |
|------|------|------|
| CRYPTO\_MODE\_SHA1 | 20 | HMAC-SHA1 |
| CRYPTO\_MODE\_SHA256 | 21 | HMAC-SHA256 |
| CRYPTO\_MODE\_SHA384 | 22 | HMAC-SHA384 |
| CRYPTO\_MODE\_SHA512 | 23 | HMAC-SHA512 |
| CRYPTO\_MODE\_MD2 | 24 | HMAC-MD2 |
| CRYPTO\_MODE\_RIPEMB128 | 26 | HMAC-RIPEMB128 |
| CRYPTO\_MODE\_RIPEMB160 | 27 | HMAC-RIPEMB160 |
| CRYPTO\_MODE\_RIPEMB256 | 28 | HMAC-RIPEMB256 |
| CRYPTO\_MODE\_RIPEMB320 | 29 | HMAC-RIPEMB320 |
| CRYPTO\_MODE\_SHA3\_224 | 30 | HMAC-SHA3-224 |
| CRYPTO\_MODE\_SHA3\_256 | 31 | HMAC-SHA3-256 |
| CRYPTO\_MODE\_SHA3\_384 | 32 | HMAC-SHA3-384 |
| CRYPTO\_MODE\_SHA3\_512 | 33 | HMAC-SHA3-512 |
| **Definition File: **[crypto.def](https://bitbucket.org/microsabio/soslib/src/master/907016/crypto.def) | |
_cbsrc _
the same as for other opcodes.
**Example**
\++include ashinc:crypto.def
map1 text\$,s,0,"The quick brown fox jumps over the lazy dog"
map1 key\$,s,64,"key"
map1 hmac\$,s,132
map1 status,i,4
\! generate HMAC-SHA256 for text\$ using key\$
xcall CRYPTO, CRYPTOP\_HMAC, status, text\$, "", hmac\$, "hex", \&
CRYPF\_NONE, CRYPTO\_CIPHER\_NA, key\$, 0, CRYPTO\_MODE\_SHA256
? "hex encoded hmac-sha256: ";hmac\$
**History**
2020 July, A-Shell 6.5.1688: The updated [ASHNET](ashnet.htm.md) 1.1.173 supports SHA3 hash algorithms in the HMAC operation via new mode parameter symbols 30 through 33.