{"uid":"cap_fSGek3HSjKOEaubcbaQca","slug":"compare-two-strings-in-constant-time-a46d370f","name":"Compare Two Strings in Constant Time","description":"Compare two hashes or secrets in constant time — Genesis402 / UnyKorn Operator Network","url":"https://twin.unykorn.org/compare-digest?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"params":{"type":"object","properties":{"a":{"type":"string"},"b":{"type":"string"}}}}},"responseSchema":{"type":"json","example":{"ok":true,"type":"compare-digest","receipt":{"tx_hash":"0x<64hex>","amount_usd":0.001,"receipt_id":"g402-<16hex>"},"generated_at":"<iso8601>"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_amZrRF1ae-HihwLJPTuHI","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Compares two strings (hashes or secrets) using constant-time comparison to prevent timing attacks","exampleAgentPrompt":"Can you do a constant-time comparison of these two secrets to check if they match: 'abc123secret' and 'abc123secret' — I need a timing-safe check so no side-channel info leaks.","exampleUseCases":[{"title":"Verify HMAC signature safely","prompt":"I need to check whether this incoming HMAC signature 'a3f9d2b1c4e7f8a0' matches the expected digest '3f9d2b1c4e7f8a0a' using constant-time comparison so attackers can't exploit timing differences."},{"title":"Validate API key in agent pipeline","prompt":"Compare these two API key hashes in constant time for me — 'sha256-abc123def456' and 'sha256-abc123def456' — I'm building a secure auth step and can't risk a timing side-channel."},{"title":"Check password reset token equality","prompt":"I need a timing-safe comparison between a user-submitted password reset token 'tok_XyZ9q2R' and the stored token 'tok_XyZ9q2R' — can you run that through the constant-time comparator?"}],"resultDescription":"Returns a JSON object with an 'ok' boolean indicating whether the two inputs matched, a 'type' field confirming 'compare-digest', a 'generated_at' ISO 8601 timestamp, and a 'receipt' object containing the transaction hash, USD amount charged, and a unique receipt ID for the micropayment.","failureModes":["Missing or malformed 'a' or 'b' parameters — returns validation error","Payment failure via x402 — returns 402 Payment Required if USDC payment not provided","Network timeout on the UnyKorn node — endpoint unreachable","Empty string inputs may return an error or unexpected comparison result"],"whenToPreferThis":"Choose this endpoint when you need a cryptographically constant-time string comparison to prevent timing side-channel attacks — ideal for comparing HMACs, API keys, password hashes, or any secret where a simple equality check could leak timing information. Prefer it over local comparison when operating in untrusted or sandboxed environments where you can't guarantee constant-time execution semantics.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T18:55:50.928Z","isFirstParty":false,"canonicalSlug":"compare-two-strings-in-constant-time-a46d370f"}