Skip to main content

Is there a way to expire a HMAC hash for identity verification? How long does the hash last if the secrets are not rotated? Rotating a secret requires downtime so it is not ideal. If a HMAC signature is leaked, it can be use by anyone to impersonate a user. Unless I am misunderstanding..

@Julia G 


Hey @Darren Zou I work on Fin AI Agent so have connected to a more relevant team to help you out with this!


Hi @Darren Zou ! Ebenezer here from Engineering Support👋.

The HMAC hash value for Identity verification doesn’t expire. If you do fear that the secret key has been leaked you would need to get in touch with us to rotate it, this can ben done in under 5-10mins.

 

Hope this helps!

 


Reply