When Razorpay signature verification fails on every payment, check that you have not swapped the HMAC key and message. The secret is the key; the string order_id + "|" + payment_id is what gets signed. Swapping them produces a valid-looking hex digest that never matches, which looks exactly like a Razorpay-side problem but is a two-line bug in your code.

Context: Stack Overflow #56573028 (answer score 15): A Node.js developer's Razorpay payment signature verification kept failing because the HMAC arguments were swapped: they passed razorpay_order_id + "|" + razorpay_payment_id as the HMAC key and the key secret as the message. The correct construction is createHmac('sha256', RAZORPAY_KEY_SECRET) with the order id, a pipe, and the payment id as the signed message.

## Matched source
Source: Published skill
Original query: "Razorpay signature never verifies: the HMAC key and message are swapped"
Key terms: hmac, message, never, razorpay, signature, swapped, verifies
