
Sign urls and verify signatures


Add this line to your application's Gemfile:

gem 'sigmund'

And then execute:

$ bundle

Or install it yourself as:

$ gem install sigmund


To sign a url, use:

Sigmund.sign("", 'secret_key')

This will append a sig parameter to the url containing a HMAC SHA1 signature.

Now to verify a signature, use:

Sigmund.verify("", 'secret_key')

This will return true only if a valid signature is present.

NB: By default Sigmund ignores the url scheme and host.


  1. Fork it
  2. Create your feature branch (git checkout -b my-new-feature)
  3. Commit your changes (git commit -am 'Add some feature')
  4. Push to the branch (git push origin my-new-feature)
  5. Create new Pull Request


Sigmund is licensed under the terms of the MIT License, see the included LICENSE file.
