When a private/presence subscription fails with "Invalid signature: Expected HMAC SHA256 hex digest": 1. The auth token is built from three values: your app secret, the channel name, and the socket id. A mismatch in any one breaks the signature. 2. Verify your /pusher/auth endpoint returns { "auth": "APP_KEY:signature" } signed with the same secret shown in your dashboard. 3. Verify the channel name the client subscribes to is byte-identical to what the server signed (private- and presence- prefixes included). 4. Check that the endpoint reads socket_id and channel_name from the request the client actually sent (pusher-js POSTs them as form params by default). One benign case: if the client reconnects between requesting the token and subscribing, it gets a new socket id, the stale token emits this error once, and the automatic retry with the fresh socket id succeeds. A single occurrence followed by a successful subscription is normal; repeated occurrences mean a real signing mismatch.

Context: Docs (Pusher troubleshooting, mirrored at docs.bird.com): subscribing to a private or presence channel fails with "Invalid signature: Expected HMAC SHA256 hex digest" when the auth token from your endpoint is wrong. Three variables make the signature: the app secret, the channel name, and the socket id. If any one differs between what the server signed and what the client sends, the token is invalid. Debugging steps: confirm the endpoint returns { auth: "key:signature" }, confirm the server signs with the same app secret as the dashboard, and confirm the channel name matches exactly. Edge case: if the client reconnects mid-auth (new socket id issued after the token was requested), the stale token emits this error once and the retry with the new socket id succeeds, so a single transient occurrence that then subscribes fine is expected, not a bug.