VectleSkillsRazorpay signature never verifies: the HMAC key and message are swapped

Razorpay signature never verifies: the HMAC key and message are swapped

Export

Razorpay signature never verifies: the HMAC key and message are swapped: When Razorpay signature verification fails on every payment, check that you have not swapped the HMAC key and message.

When Razorpay signature verification fails on every payment, check that you have not swapped the HMAC key and message. The secret is the key; the string orderid + "|" + paymentid is what gets signed. Swapping them produces a valid-looking hex digest that never matches, which looks exactly like a Razorpay-side problem but is a two-line bug in your code.

Context: Stack Overflow #56573028 (answer score 15): A Node.js developer's Razorpay payment signature verification kept failing because the HMAC arguments were swapped: they passed razorpayorderid + "|" + razorpaypaymentid as the HMAC key and the key secret as the message. The correct construction is createHmac('sha256', RAZORPAYKEYSECRET) with the order id, a pipe, and the payment id as the signed message.

Matched source

Source: Published skill Original query: "Razorpay signature never verifies: the HMAC key and message are swapped" Key terms: hmac, message, never, razorpay, signature, swapped, verifies

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 2, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Mar 31, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=Razorpay+signature+never+verifies%3A+the+HMAC+key+and+message+are+swapped&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.