hmac

Returns the keyed-hash message authentication code (HMAC) of message using key and the given hash algorithm. The result is returned as raw MAC bytes; wrap it with :func:hex or :func:base64 for a textual value. The default algorithm is SHA-256.

An HMAC verifies both the integrity and the authenticity of a message using a shared secret key: a recipient who holds the same key can recompute the code and confirm the message was not altered and came from a party that knows the key. Common uses include signing API requests, validating webhook payloads, and deriving signing keys by chaining HMAC calls (for example, AWS Signature Version 4).

Syntax

from pyspark.sql import functions as sf

sf.hmac(key, message, algorithm=None)

Parameters

Parameter Type Description
key pyspark.sql.Column or str The secret key, as a binary value.
message pyspark.sql.Column or str The message to authenticate, as a binary value.
algorithm pyspark.sql.Column or str, optional The hash algorithm. Valid values: SHA-224, SHA-256, SHA-384, SHA-512, SHA-1, MD5. The default is SHA-256.

Returns

pyspark.sql.Column: A new column that contains the raw HMAC bytes.

Examples

Example 1: Compute the HMAC with the default SHA-256 algorithm

from pyspark.sql import functions as sf
df = spark.createDataFrame([("key", "message")], ["key", "message"])
df.select(sf.hex(sf.hmac(df.key, df.message))).show(truncate=False)
+----------------------------------------------------------------+
|hex(hmac(key, message, SHA-256))                                |
+----------------------------------------------------------------+
|6E9EF29B75FFFC5B7ABAE527D58FDADB2FE42E7219011976917343065F58ED4A|
+----------------------------------------------------------------+

Example 2: Compute the HMAC with an explicit algorithm

from pyspark.sql import functions as sf
df = spark.createDataFrame([("key", "message")], ["key", "message"])
df.select(sf.hex(sf.hmac(df.key, df.message, sf.lit("SHA-1")))).show(truncate=False)
+----------------------------------------+
|hex(hmac(key, message, SHA-1))          |
+----------------------------------------+
|2088DF74D5F2146B48146CAF4965377E9D0BE3A4|
+----------------------------------------+