Overview
Returns the HMAC signature in hex or base64 encoding. Use for signing API requests, validating webhooks, or any scenario requiring message authentication.
Live Test HMAC Signing Skill Skill →
The tool
Once your client is connected to the VerveKit server, this appears in its tool list as HMACSigningSkill. It is read-only and open-world — it fetches and never mutates anything on your side — so most clients call it without asking you to confirm.
{
"name": "HMACSigningSkill",
"arguments": {
"message": "Hello World",
"secret": "my-secret-key"
}
}You do not name the tool yourself; the model picks it. Asking about Hello World in the terms this skill covers is enough for it to reach for HMACSigningSkill on its own — naming it explicitly also works, and is the way to force the call.
Connecting
One server URL covers every skill in the catalog, including this one. Authorization is OAuth: the client opens a browser once, and there is no key to paste into a config file.
{
"mcpServers": {
"vervekit": {
"url": "https://api.vervekit.com/v1/mcp"
}
}
}https://api.vervekit.com/v1/mcpPer-client setup — Claude, Cursor, VS Code, ChatGPT — is on the MCP setup page.
Arguments
These are the properties on the tool's inputSchema, so a well-behaved client validates them before the call is made. Premium arguments are accepted on every plan but only take effect on plans that include them.
| Argument | Type | Description |
|---|---|---|
messageRequired | string | The message to sign |
secretRequired | string | The secret key for HMAC generation |
algorithmOptional | string | Hash algorithm to usesha256sha384sha512sha1md5default sha256 |
encodingOptional | string | Output encoding formathexbase64default hex |
What the model gets back
The result carries a structuredContent object matching the tool's declared outputSchema, so a client reads fields without parsing prose. status is "ok" and error is null on success; a null field means the value was not available for that input, not that the call failed.
{
"status": "ok",
"error": null,
"data": {
"hmac": "2cd7c25025198d4458002ceb064ad37ccfbbe46650876d693f5e080bd954e449",
"algorithm": "sha256",
"encoding": "hex"
}
}
Response fields
Paths are relative to data. Premium fields are absent rather than zeroed on plans that do not include them, so check for presence instead of comparing to 0.
| Field | Type | Example | Description |
|---|---|---|---|
hmac | string | 2cd7c25025198d4458002ceb064ad37ccfbbe46650876d693f5e080bd954e449 | Generated HMAC signature in specified encoding format |
algorithm | string | sha256 | Hash algorithm used for HMAC generation |
encoding | string | hex | Output encoding format applied to the signature |
Failure modes
Errors come back as tool errors carrying a sentence the model can act on, not a bare status code. Error handling covers the full list.
| Status | What it means |
|---|---|
400 / 422 | The arguments did not validate. The message names the offending one. |
401 | The OAuth session is invalid or expired — reconnect the server. |
403 | Blocked by a key restriction or an IP allow-list. Never a bad identity. |
404 | This skill is not part of VerveKit. Check the catalog. |
429 | Out of credits, or a brief rate limit. The message tells them apart. |
A call costs 2 credits each time the tool actually runs; a model that reasons about the tool without calling it costs nothing.
Use cases
- API Authentication
- Sign API requests to prove authenticity
- Webhook Verification
- Validate incoming webhooks from services like Stripe, GitHub
- Data Integrity
- Ensure messages haven't been tampered with
- JWT Signing
- Generate signatures for JSON Web Tokens
Other ways to use HMAC Signing Skill
Set up HMAC Signing Skill on VerveKit, or reach the same source a different way. Your VerveKit account and credits work on all of them — one key, one balance.
Related
More in Security: