# llHMAC

*LSL function*

```lsl
string string llHMAC(string private_key, string msg, string algorithm);
```

- `string private_key`: PEM-formatted secret key to use for the HMAC hash.
- `string msg`: Message string to be hashed.
- `string algorithm`: Cryptographic digest algorithm to use.

- Returns: `string`
- Energy: 10

This function supports md5, sha1, sha224, sha256, sha384, sha512 for **algorithm**.

**secret** can be any string.

Returns a [string](https://wiki.secondlife.com/wiki/string) that is the [Base64-encoded](https://en.wikipedia.org/wiki/Base64) [HMAC](https://en.wikipedia.org/wiki/HMAC) hash of **msg** when using hash **algorithm** **algorithm** and secret string **secret**.

```lsl title="How to use" frame="terminal"
string result = llHMAC("", "", "");
```

## Caveats

- **secret** is passed in as UTF-8 (though stored in memory as UTF-16 in Mono).
- If your secret is encoded in Base64 (as is common for HMAC applications), consider [llBase64ToString](/functions/llBase64ToString/), but be aware of its caveats.
- If you are generating an HMAC hash on a different platform, you will need to ensure its implementation reads the secret as UTF-8 (or you will need to manually encode it into the correct format beforehand), or else the HMAC hashes will not match.
- Since **secret** is not Base64, and LSL does not support "NUL" (U+0000) in strings, this function cannot calculate hashes with secrets that encode into UTF-8/16 as U+0000.

## Examples

<details open>
<summary>Example 1</summary>

```lsl collapse={16-20}
default
{
    state_entry()
    {
        string secret = "secret key";

        // Supported algorithims for llHMAC() include:
        // md5, sha1, sha224, sha256, sha384, sha512

        string algorithm = "sha1";
        string msg = "Hello, Avatar!";

        string digest = llHMAC(secret, msg, algorithm);

        // For the given secret/msg/algorithm, expect the HMAC
        // digest to be 'ffCDntkagRO5mIEtd2tYzM2Bg8I='
        llSay(0, "HMAC digest of message '" + msg + "' using algorithm "
            +  algorithm + " is " + digest);
    }
}
```

</details>

## Notes

- This function performs no checks on **secret**; it can contain any value, or no value at all. Be sure to check that you are hashing using the correct **secret**.
- Since this function uses UTF-8 secrets, you should at a minimum follow "password rules": more entropy is usually better. If you need a guideline, 32+ random characters is likely enough.

## See also

### Functions

- [llSignRSA](/functions/llSignRSA/)
- [llVerifyRSA](/functions/llVerifyRSA/)
- [llSHA1String](/functions/llSHA1String/)
- [llSHA256String](/functions/llSHA256String/)
- [llMD5String](/functions/llMD5String/)

---

*Source: [LlHMAC](https://wiki.secondlife.com/wiki/LlHMAC) on the Second Life Wiki. Content from the Second Life Wiki article LlHMAC (revision 1219022, 2026-09-08), CC BY-SA 3.0.*

---

From lsl.dev: https://lsl.dev/functions/llHMAC/
