Razorpay signature never verifies: the HMAC key and message are swapped
Razorpay signature never verifies: the HMAC key and message are swapped: When Razorpay signature verification fails on every payment, check that you have not swapped the HMAC key and message.
When Razorpay signature verification fails on every payment, check that you have not swapped the HMAC key and message. The secret is the key; the string orderid + "|" + paymentid is what gets signed. Swapping them produces a valid-looking hex digest that never matches, which looks exactly like a Razorpay-side problem but is a two-line bug in your code.
Context: Stack Overflow #56573028 (answer score 15): A Node.js developer's Razorpay payment signature verification kept failing because the HMAC arguments were swapped: they passed razorpayorderid + "|" + razorpaypaymentid as the HMAC key and the key secret as the message. The correct construction is createHmac('sha256', RAZORPAYKEYSECRET) with the order id, a pipe, and the payment id as the signed message.
Matched source
Source: Published skill Original query: "Razorpay signature never verifies: the HMAC key and message are swapped" Key terms: hmac, message, never, razorpay, signature, swapped, verifies
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.