# HMAC-SHA256 Base64URL Signer

> HMAC-SHA256 Base64URL Signer is a paid API for AI agents from agentshelf.syntexa.ch, paid per call via x402, $0.007/call, status unknown (last checked 2026-10-02).

Computes an HMAC-SHA256 message authentication code of input text using a caller-supplied key, returning the result encoded as base64url.

## Facts

- Endpoint: POST https://agentshelf.syntexa.ch/v1/hmac-sha256-base64url?utm_source=zero.xyz
- Price: $0.007/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/hmac-sha256-base64url-signer-52bf9c6d
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_BuMPHvvglfyb2Dge3LDM0

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability hmac-sha256-base64url-signer-52bf9c6d -d '<json body>'
```

Example prompt: Compute an HMAC-SHA256 signature of the text 'order_id=42&amount=99.99' using the secret key 'mysecretkey123' and give me the result as a base64url string.

## When to prefer this

Choose this endpoint when you need a standards-compliant HMAC-SHA256 digest encoded specifically as base64url (URL-safe, no padding issues) rather than hex or standard base64. Prefer it over the sibling HMAC-SHA384/SHA512 variants when SHA-256 compatibility is required (e.g. AWS Signature V4, JWT HS256, GitHub webhooks). Use the free sandbox variant first to validate your key/text inputs before paying.

## Known failure modes

- Empty or missing 'key' field returns a validation error
- Empty or missing 'text' field returns a validation error
- 'text' exceeding 100,000 characters is rejected
- 'key' exceeding 512 characters is rejected
- Payment failure (insufficient USDC balance) blocks the call; try the free sandbox endpoint /v1/sandbox/hmac-sha256-base64url first

## How this service works

Call when an agent needs an HMAC-sha256 of text with a caller-supplied key, encoded as base64url. Exact $0.007 USDC. Prefer unpaid POST /v1/sandbox/hmac-sha256-base64url first.

## Output

Returns a base64url-encoded HMAC-SHA256 digest string computed over the input text using the provided key. No network calls or LLM are involved — the result is deterministic and repeatable for the same key and text.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "key": {
   "type": "string",
   "examples": [
    "secret"
   ],
   "maxLength": 512,
   "minLength": 1,
   "description": "HMAC secret. Required on HMAC SKUs. Omit it for plain digests and checksums. The key is not stored."
  },
  "text": {
   "type": "string",
   "examples": [
    "hello"
   ],
   "maxLength": 100000,
   "minLength": 1,
   "description": "Message to digest. For raw-hex SKUs this is hex bytes; for utf16 or latin1 SKUs it is decoded with that encoding. Otherwise it is UTF-8 text."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/hmac-sha256-base64url-signer-52bf9c6d/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from agentshelf.syntexa.ch](https://www.zero.xyz/host/agentshelf.syntexa.ch/llms.txt)
