> ## Documentation Index
> Fetch the complete documentation index at: https://docs.novu.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> Turn on HMAC for Web Chat before you ship: subscriberHash on NovuProvider and agentHash on useWebChat.

HMAC (Hash-based Message Authentication Code) is off by default. Turn it on before you ship. Web Chat can require two hashes, and each hash has its own dashboard toggle.

| Hash             | Toggle                      | Input            | Where the client passes it |
| ---------------- | --------------------------- | ---------------- | -------------------------- |
| `subscriberHash` | **Novu In-App** integration | `subscriberId`   | `NovuProvider`             |
| `agentHash`      | **Web Chat** integration    | agent identifier | `useWebChat`               |

Both hashes use the environment API secret from [API Keys](https://dashboard.novu.co/api-keys). Compute them on your server. Do not compute them in the browser.

If only one toggle is on, pass only that hash. If both toggles are on, pass both hashes.

## subscriberHash

`subscriberHash` authenticates the signed-in subscriber. Without it, another person can guess a `subscriberId` and open that subscriber's session, including Web Chat.

If **Security HMAC encryption** is on for **Novu In-App**, pass `subscriberHash` to `NovuProvider`. The hash is `HMAC-SHA256(secretKey, subscriberId)` as a lowercase hex string.

```tsx theme={null}
<NovuProvider
  applicationIdentifier="YOUR_APPLICATION_IDENTIFIER"
  subscriber="YOUR_SUBSCRIBER_ID"
  subscriberHash="YOUR_SUBSCRIBER_HASH"
>
  <Chat />
</NovuProvider>
```

Generation recipes (Node.js, Python, and more): [Secure your Inbox with HMAC](/platform/inbox/prepare-for-production#secure-your-inbox-with-hmac-encryption).

## agentHash

`agentHash` authenticates which agent the subscriber can talk to. Without it, a client can send any public agent identifier that is linked to Web Chat.

If **Security HMAC encryption** is on for **Web Chat**:

1. Open [Integrations](https://dashboard.novu.co/integrations).
2. Select the **Web Chat** integration.
3. Enable **Security HMAC encryption**.
4. On your server, compute `HMAC-SHA256(secretKey, agentIdentifier)` as a lowercase hex string.
5. Pass that value as `agentHash` to `useWebChat`.

```tsx theme={null}
useWebChat({
  agentId: 'YOUR_AGENT_IDENTIFIER',
  agentHash: 'YOUR_AGENT_HASH',
});
```
