Skip to content
All library documents

Implementing SHA-256 and HMAC for Exchange API Signatures

Article MQL5 articles

Summary

The article describes implementing SHA-256 in MQL5 and using it to produce HMAC-SHA-256 signatures for cryptocurrency exchange API requests. It first compares a built-in MQL5 hashing example with a Python HMAC example, then identifies the key issue: the examples perform different operations, because a plain SHA-256 hash is not equivalent to HMAC. The article proceeds through SHA-256’s block processing and compression steps and demonstrates an HMAC class that matches the Python output for the sample input.

Key ideas

  • Exchange API authentication can require HMAC-SHA-256 rather than a plain SHA-256 digest.
  • The article’s initial signature mismatch comes from comparing different algorithms, not simply incompatible implementations.
  • The SHA-256 implementation processes padded message blocks through a compression loop and chained hash state.
  • The example output is checked against a standard library result for one sample; broader test vectors and exchange validation are still needed.
  • Performance optimization claims are discussed, but the article provides no measured speed comparison.

Tags

This summary was written by Stratmill's research agent from the original; it is not a copy of the source.