# js-crypto-hmac

> Universal Module for HMAC (Hash-based Message Authentication Code) in JavaScript

Latest version **1.0.7** (published 2023-09-27) · MIT license · 0 weekly downloads

## Install

```sh
npm install js-crypto-hmac
pnpm add js-crypto-hmac
yarn add js-crypto-hmac
bun add js-crypto-hmac
```

## Health

**Score 25/100 (F)** — status: abandoned.

Positive: has types; no vulnerabilities; high quality score.

Warnings: low downloads; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.7 |
| Published | 2023-09-27 |
| First published | 2018-09-26 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | CommonJS |
| Dependencies | 2 |
| Unpacked size | 82.6 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | Jun Kurihara |
| Maintainers | kurihara |
| Keywords | crypto, hmac, webcrypto |

## Links

- npm: https://www.npmjs.com/package/js-crypto-hmac
- Repository: https://github.com/junkurihara/jscu
- Homepage: https://github.com/junkurihara/jscu/tree/master/packages/js-crypto-hmac#readme
- Issues: https://github.com/junkurihara/jscu/issues
- npm.io page: https://npm.io/package/js-crypto-hmac

## Dependencies (2)

- [js-crypto-env](https://npm.io/package/js-crypto-env.md) ^1.0.5
- [js-crypto-hash](https://npm.io/package/js-crypto-hash.md) ^1.0.7

## Alternatives

- [@gemini-wallet/core](https://npm.io/package/@gemini-wallet/core.md) — 515.6K weekly downloads
- [utility](https://npm.io/package/utility.md) — 416.6K weekly downloads
- [@primno/dpapi](https://npm.io/package/@primno/dpapi.md) — 7.2K weekly downloads
- [pi-readseek](https://npm.io/package/pi-readseek.md) — 3.7K weekly downloads
- [@emilia-protocol/verify](https://npm.io/package/@emilia-protocol/verify.md) — 1.1K weekly downloads

## Recent versions

- 1.0.7 (latest) — 2023-09-27
- 1.0.6 — 2023-09-02
- 1.0.5 — 2023-08-25
- 1.0.4 — 2022-02-04
- 1.0.3 — 2021-11-22
- 1.0.2 — 2021-03-13
- 1.0.1 — 2021-03-13
- 1.0.0 — 2020-09-30
- 0.6.3 — 2020-01-14
- 0.6.2 — 2019-12-08
- 0.6.1 — 2019-11-19
- 0.6.0 — 2019-11-19
- 0.5.3 — 2019-08-14
- 0.5.2 — 2019-07-19
- 0.5.1 — 2019-07-13
- … 24 more at https://npm.io/package/js-crypto-hmac/versions

## README

Universal Module for HMAC (Hash-based Message Authentication Code) in JavaScript
--
[![npm version](https://badge.fury.io/js/js-crypto-hmac.svg)](https://badge.fury.io/js/js-crypto-hmac)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)

> **WARNING**: At this time this solution should be considered suitable for research and experimentation, further code and security review is needed before utilization in a production application.

# Introduction and Overview

This library is designed to 'universally' provide HMAC (Hash-based Message Authentication Code) functions, i.e., it works both on most modern browsers and on Node.js just by importing from NPM/source code. Note that in the design principle, the library fully utilizes native APIs like WebCrypto API to accelerate its operation if available.

# Installation

At your project directory, do either one of the following.

- From npm/yarn:
  ```shell
  $ npm install --save js-crypto-hmac // npm
  $ yarn add js-crypto-hmac // yarn
  ```
- From GitHub:
  ```shell
  $ git clone https://github.com/junkurihara/jscu.git
  $ cd js-crypto-utils/packages/js-crypto-hmac
  & yarn build
  ```

Then you should import the package as follows.

```shell
import hmac from 'js-crypto-hmac'; // for npm
import hmac from 'path/to/js-crypto-hmac/dist/index.js'; // for github
```

The bundled file is also given as `js-crypto-hmac/dist/jschmac.bundle.js` for a use case where the module is imported as a `window.jschmac` object via `script` tags.


# Usage

## Compute Keyed-Hash (Message Authentication Code) of a Message

```javascript
const msg = ...; // Uint8Array of arbitrary length
const key = ...; // Uint8Array of 32 bytes (since SHA-256 is used)
const hash = 'SHA-256';
hmac.compute(key, msg, hash).then( (hmac) => {
  // now you get a keyed-hash of msg in Uint8Array
});
```

## Verify Keyed-Hash

```javascript
const msg = ...; // Uint8Array of arbitrary length
const key = ...; // Uint8Array of 32 bytes (since SHA-256 is used)
const mac = ...; // computed keyed hash in Uint8Array
const hash = 'SHA-256';
hmac.verify(key, msg, mac, hash).then( (result) => {
  // now you get true or false as the result of verification
});
```

# License

Licensed under the MIT license, see `LICENSE` file.

---
_Source: https://npm.io/package/js-crypto-hmac · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
