Authentication & security

HMAC-SHA256

HMAC-SHA256 is a keyed message authentication construction that combines a shared secret with SHA-256 to produce a value used to verify message integrity and authenticity.

Also found under: HMAC, Message authentication code

How it works

A verifier with the same secret can recompute the result and detect a changed message or an invalid signature. HMAC does not encrypt the message or independently decide whether a user deserves access. The server must make that permission decision before signing the subscription data.

In a Pubb integration

Pubb uses HMAC-SHA256 for private and presence channel signatures. Prefer a server SDK or the documented authorization endpoint so socket IDs, channel names and presence data use the expected format.

Understand channel access

A practical example

A signature produced for one socket and private channel should not be treated as a reusable login token for every channel or a later replacement connection.