# Approach for signing message with HMAC (any recommendation for third party node?)

**URL:** <https://discourse.nodered.org/t/approach-for-signing-message-with-hmac-any-recommendation-for-third-party-node/86058>\
**Category:** General\
**Created:** [1 March 2024 14:49 UTC](https://discourse.nodered.org/t/approach-for-signing-message-with-hmac-any-recommendation-for-third-party-node/86058 "2024-03-01T14:49:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![escapist3734](https://avatars.discourse-cdn.com/v4/letter/e/4da419/32.png) [@escapist3734](https://discourse.nodered.org/u/escapist3734)\
**Post date:** [1 March 2024 14:49 UTC](https://discourse.nodered.org/t/approach-for-signing-message-with-hmac-any-recommendation-for-third-party-node/86058/1 "2024-03-01T14:49:43Z")

</div>

Hi!

I have a Python script that I would like to integrate into Node-RED. Essentially, it signs a message with HMAC/SHA256.

So far, I've attempted to implement Crypto-JS to create a function in Node-RED. However, this approach isn't very flexible if I want to share the flow with others and also I'havent succeed ☹

Perhaps someone has created a similar example using a third-party flow and can assist or guide me through the process.

```auto
def mymessagesigned(mysecret, message, randomh):
    random_header_bytes = randomh.encode('utf-8')
    shared_secret_bytes = mysecret.encode('utf-8')
    signature = hmac.new(shared_secret_bytes, digestmod=hashlib.sha256)
    signature.update(random_header_bytes)
    signature.update(message.encode('utf-8'))
    
    return signature.hexdigest()

```

thank you

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [1 March 2024 18:51 UTC](https://discourse.nodered.org/t/approach-for-signing-message-with-hmac-any-recommendation-for-third-party-node/86058/2 "2024-03-01T18:51:12Z")

</div>

> [@escapist3734](#):
>
> However, this approach isn't very flexible if I want to share the flow with others and also I'havent succeed ☹

Why not? You can simply add crypto to a function nodes settings tab. The flow will be exportable and importable by anyone who you share it with.

> [@escapist3734](#):
>
> Perhaps someone has created a similar example using a third-party flow

Have you tried the existing contrib nodes? [Library - Node-RED](https://flows.nodered.org/search?term=Hmac&type=node)

---

<div class="post-metadata">

**Author:** ![escapist3734](https://avatars.discourse-cdn.com/v4/letter/e/4da419/32.png) [@escapist3734](https://discourse.nodered.org/u/escapist3734)\
**Post date:** [1 March 2024 19:05 UTC](https://discourse.nodered.org/t/approach-for-signing-message-with-hmac-any-recommendation-for-third-party-node/86058/3 "2024-03-01T19:05:15Z")

</div>

THX for the info

I only read the "functionglobacontext" but didn't read further  
[https://nodered.org/docs/user-guide/writing-functions#loading-additional-modules](https://nodered.org/docs/user-guide/writing-functions#loading-additional-modules)

With the settings tab it`s easy 🙂 thx

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [15 March 2024 19:05 UTC](https://discourse.nodered.org/t/approach-for-signing-message-with-hmac-any-recommendation-for-third-party-node/86058/4 "2024-03-15T19:05:26Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
