Tick the HMAC option
It is already switched on for you on this page, with an example key and message.
Enter a message and a secret key and get the HMAC signature with SHA-1, SHA-256, SHA-384 and SHA-512. The key and the message stay in your browser.
100% private — text and files are hashed in your browser and never uploaded.
Keep going with your result in another tool. Nothing is uploaded.
It is already switched on for you on this page, with an example key and message.
Type the exact message (the request body, for example) and your secret key.
Copy the HMAC-SHA256 you need, in hexadecimal or Base64.
To generate an HMAC-SHA256, write your message in the text box, switch on the HMAC option, type your secret key and copy the HMAC-SHA-256 line. With the key secret and the message message, the result is 8b5f48702995c1598c573db1e21866a9b825d4a794d169d7060a03605796360b. The signature is computed in your browser, so the key is never sent anywhere.
HMAC stands for hash-based message authentication code and is defined in RFC 2104. It mixes a secret key into a hash function so that the result proves two things at once: the message has not been altered, and whoever produced the signature knows the key. A plain hash proves only the first, because anyone can compute it.
To verify a webhook, compute the HMAC of the exact raw request body with your shared secret and compare it with the signature you received. Use a constant-time comparison in your code, and never re-serialise the JSON first, because a single changed space changes the whole HMAC. This page is ideal for reproducing a signature by hand when a webhook check keeps failing.
Use a plain SHA-256 to fingerprint content anyone can see, such as a file download. Use HMAC-SHA256 whenever the fingerprint must be unforgeable without a secret. Never build your own scheme by hashing the key and the message together; HMAC was designed to avoid the length-extension weakness that scheme has.
The hash is computed by your own browser with the Web Crypto API (and a built-in routine for MD5, which Web Crypto does not offer). Nothing you type and no file you drop is sent to a server, so it is safe to hash private text and internal files.
More utilities that also run without leaving your browser.