Seriously, HMAC was built for this exact purpose. The primary design goal of HMAC was to combat insecure ad-hoc keyed hash schemes exactly like this. I saw this a couple months ago on moonshado's SMS API and after going back and forth with someone from their team I just let it go because they obviously didn't get it. For anyone who cares about security, this is a huge red flag.