The HmacImportParams dictionary of the Web Crypto API represents the object that should be passed as the algorithm parameter into SubtleCrypto.importKey() or SubtleCrypto.unwrapKey(), when generating a key for the HMAC algorithm.
nameA string. This should be set to HMAC.
hashA string or an object containing a single property called name with a string value. It is an identifier for the digest algorithm to use. This should be one of the following:
SHA-256: selects the SHA-256 algorithm.SHA-384: selects the SHA-384 algorithm.SHA-512: selects the SHA-512 algorithm.Warning: SHA-1 is also supported here but the SHA-1 algorithm is considered vulnerable and should no longer be used.
length OptionalA Number representing the length in bits of the key. If this is omitted the length of the key is equal to the length of the digest generated by the digest function you have chosen. Unless you have a good reason to use a different length, omit this property and use the default.
See the examples for SubtleCrypto.importKey().
| Specification |
|---|
| Web Cryptography Level 2> # dfn-HmacImportParams> |
Browsers that support the "HMAC" algorithm for the SubtleCrypto.importKey(), SubtleCrypto.unwrapKey() methods will support this type.
© 2005–2025 MDN contributors.
Licensed under the Creative Commons Attribution-ShareAlike License v2.5 or later.
https://developer.mozilla.org/en-US/docs/Web/API/HmacImportParams