The Crypto steps do what a partner's API (application programming interface) or webhook often asks for: a SHA-256 hash, an HMAC signature in a header, a Base64 value, a signed JWT (JSON Web Token). Each one is its own step, and none needs a connection.

Who can do this

Workspace Admins and Editors, on every plan.

The steps

Step What it does Result
Hash Makes a fingerprint of text — SHA-256 (the default), SHA-512, SHA-1 · for checksums, not security or MD5 · for checksums, not security, written as Hex or Base64. Text
Make an HMAC signature Signs text with a secret, as webhooks are signed, with SHA-256, SHA-512 or SHA-1. Text
Encode Base64 / Decode Base64 Turns text into Base64, and Base64 back into text. Text
URL-encode / URL-decode Makes text safe to put in a web address, and turns it back. Text
Make a random string A code, a token, a password, of the Length you choose — 32 unless you change it, up to 256. Text
Make a UUID Makes a new unique id, such as 3f2b8c1e-5d7a-4c2b-9e41-0a6f1d2c8b77. Text
Sign a JWT Makes a signed JSON Web Token with the claims you give, with HS256 or RS256. Text
Check a JWT Checks a token’s signature and expiry, and reads its claims. True or false, with the claims

Steps

  1. Select + where the value is needed. In the step picker, open Utilities, select Crypto — No connection needed — then the step. Or search for the step's name, such as hash or JWT.
  2. Put in what to work on — Text for most steps, Text to sign for Make an HMAC signature, Token for Check a JWT. Drag it in from Data from earlier steps or use {{ }} — for a webhook's body, {{ trigger.body }}. Make a random string, Make a UUID and Sign a JWT need nothing to start from.
  3. Fill in the step's own settings:
    • Hash and Make an HMAC signature — Algorithm, and Write it as: Hex (the default) or Base64.
    • Make a random string — Length, and Characters: Letters and digits (the default), Letters, Digits, Hex (0–9, a–f) or Letters, digits and symbols.
    • Sign a JWT and Check a JWT — Algorithm: HS256 · a shared secret (the default) or RS256 — RS256 · a private key to sign, RS256 · a public key to check.
  4. For Make an HMAC signature, type the secret in Secret. For Sign a JWT and Check a JWT, fill in Key: HS256: the shared secret. RS256: the private key (to sign) or the public key (to check), in PEM form. Once saved, the box shows dots and Replace, with Stored encrypted. It is never shown again after you save.
  5. For Sign a JWT, add the claims under Claims, a row each — a name such as sub and its value, such as rohan@consulace.com — with Add a field for the next. Set Expires in, in minutes: 60 unless you change it; empty, it never expires.
  6. In Put the result in, keep the suggested field name or type your own. The item's other fields are kept. (Check a JWT has no Put the result in; see Output.)
  7. Select Run this step, then check Output.

Output

The result goes under the field you named — by default value. Every other field on the item is kept; a field already called that is replaced. Hex is written in lower case.

Check a JWT adds valid (true or false), claims (what the token holds) and expiresAt (its expiry as an ISO date, or empty when it has none) to the item. When the token is not valid, it also adds reason, such as Expired, Not valid yet, The signature does not match the key. or Not a JWT — it should have three parts separated by dots. A token that is not valid never fails the step; add an IF after it on valid to stop a request whose token is not valid. Do not trust claims when valid is false.

Good to know

  • A secret is kept like a connection's. It is encrypted when you save, never shown again, and never put on the item, in the run's record or within reach of the Code step. Copying the step or the workflow, exporting it to a file, sharing it as a template or using Describe it on it leaves the secret out: the copy says This step’s secret wasn’t copied. Type it again to use the step. and shows Needs setup until someone types it again.
  • Use SHA-256 or SHA-512 for anything that matters. SHA-1 and MD5 are offered because older services still ask for them as checksums.
  • The exact text matters for a signature. A partner that signs the raw body expects the body exactly as it arrived. A JSON body is read into fields, so {{ trigger.body }} gives it back without its original spacing — check the signature against one real request before you rely on it.
  • Sign a JWT always adds iat (when it was made) and, with Expires in, exp. A claim whose value is a whole number, true or false keeps that type.
  • Check a JWT wants the token alone. An Authorization header that starts with Bearer needs that word taken off first, with the Text tool's Replace — see Change, split or clean up text.
  • Decode Base64 gives text, and reads the URL-safe form too. For a Base64 file, the step that brought it usually gives the file itself — see Pass files between steps. URL-decode turns + into a space.
  • Random strings and UUIDs come from a cryptographic random source, so they are safe to use as tokens.
  • It runs once per item.

If something goes wrong

What the run says Why What to do
Text is not Base64. Check the value from the earlier step. Decode Base64 got text that is not Base64. Check the step's Input.
Key is not an RSA private key in PEM form (-----BEGIN PRIVATE KEY-----). Sign a JWT with RS256, and Key holds something else. Replace the key with the whole private key, including its -----BEGIN and -----END lines.
valid false, reason Key is not an RSA public key in PEM form (-----BEGIN PUBLIC KEY-----). Check a JWT with RS256, and Key holds something else. Replace it with the whole public key.
valid false, reason Signed with …, not HS256. (or RS256) The token was signed with another algorithm. Choose the algorithm the token uses.
Secret wasn't copied with this step. Type it again to use the step. (or Key), and Needs setup on the step The step came from a copy, an export, a template or Describe it. Type the secret again.
Secret is empty. Type it in the step's settings. (or Key) No secret was typed. Type it in.
Secret could not be read. Type it again in the step's settings. (or Key) The stored secret can no longer be read. Replace it.
Token is empty when the step ran — an earlier step may not have given the value it names. Token names a value the item does not have. Check the step's Input; correct the value in {{ }}.
Length “…” is not a whole number from 1 to 256. Make a random string's Length is out of range. Use a whole number from 1 to 256.
Expires in “…” is not a whole number from 1 to 525,600. Expires in is not a whole number of minutes, up to a year. Correct it, or leave it empty for no expiry.