HMAC Generator - HMAC-SHA256, SHA-1, SHA-384 & SHA-512 Online
HMAC Generator
Sign a message with a secret key and verify webhooks and API requests
Live HMAC
The result updates as you type. Choose SHA-1, SHA-256, SHA-384 or SHA-512.
Text, Hex or Base64 Keys
Enter the key as plain text or as raw bytes in hex or base64, the way most providers publish their secrets.
Verify a Signature
Paste the signature you received and see at once whether it matches, in hex or base64.
Full Privacy
Uses your browser's built-in Web Crypto API. Neither the key nor the message leaves your device.
What an HMAC Is For
An HMAC (hash-based message authentication code) proves that a message came from someone who knows a shared secret and was not changed on the way. It is how webhook providers sign their calls, how many APIs authenticate requests and how JWTs with the HS256 algorithm are signed. The sender computes the HMAC of the message with the secret and sends it along; the receiver repeats the calculation and compares.
Use SHA-256 or stronger for anything new; HMAC-SHA1 is still considered safe for authentication but is being phased out. MD5 is not offered because the browser's Web Crypto API does not provide it. An empty key is allowed and behaves like a key of one zero byte. Keep real secrets out of shared screens and screenshots, and compare signatures in constant time in your own code.
Key Takeaways
- Standard: Implements RFC 2104 and matches the RFC 4231 test vectors.
- Any encoding: Keys in UTF-8, hex or base64; output in hex, HEX, base64 or base64url.
- Related tools: For plain digests use the Hash Generator; for token payloads use the JWT Decoder.