HMAC generator (HMAC-SHA256 and more)

Enter a message and a secret key and get the HMAC signature with SHA-1, SHA-256, SHA-384 and SHA-512. The key and the message stay in your browser.

  • Free
  • No sign-up
  • Runs in your browser
hmac-generator

100% private — text and files are hashed in your browser and never uploaded.

How it works

Tick the HMAC option

It is already switched on for you on this page, with an example key and message.

Enter the message and the key

Type the exact message (the request body, for example) and your secret key.

Copy the signature

Copy the HMAC-SHA256 you need, in hexadecimal or Base64.

How to generate an HMAC-SHA256

To generate an HMAC-SHA256, write your message in the text box, switch on the HMAC option, type your secret key and copy the HMAC-SHA-256 line. With the key secret and the message message, the result is 8b5f48702995c1598c573db1e21866a9b825d4a794d169d7060a03605796360b. The signature is computed in your browser, so the key is never sent anywhere.

What is an HMAC?

HMAC stands for hash-based message authentication code and is defined in RFC 2104. It mixes a secret key into a hash function so that the result proves two things at once: the message has not been altered, and whoever produced the signature knows the key. A plain hash proves only the first, because anyone can compute it.

Where HMAC signatures are used

  • Webhooks: Stripe, GitHub, Shopify and many others sign each request, for example in the X-Hub-Signature-256 header, so that your server can check who sent it.
  • API request signing: AWS Signature Version 4 chains several HMAC-SHA256 steps.
  • JSON Web Tokens: the HS256 algorithm is HMAC-SHA256 over the token header and payload.
  • Session cookies and one-time links, which are often protected with an HMAC so that users cannot tamper with them.

Checking a signature safely

To verify a webhook, compute the HMAC of the exact raw request body with your shared secret and compare it with the signature you received. Use a constant-time comparison in your code, and never re-serialise the JSON first, because a single changed space changes the whole HMAC. This page is ideal for reproducing a signature by hand when a webhook check keeps failing.

HMAC or plain hash?

Use a plain SHA-256 to fingerprint content anyone can see, such as a file download. Use HMAC-SHA256 whenever the fingerprint must be unforgeable without a secret. Never build your own scheme by hashing the key and the message together; HMAC was designed to avoid the length-extension weakness that scheme has.

Private by design

The hash is computed by your own browser with the Web Crypto API (and a built-in routine for MD5, which Web Crypto does not offer). Nothing you type and no file you drop is sent to a server, so it is safe to hash private text and internal files.

Frequently asked questions

Which HMAC algorithm should I use?
HMAC-SHA256 is the standard choice and what most services expect. HMAC-SHA512 gives a longer signature, and HMAC-SHA1 is only for older systems that still require it.
Is it safe to type my secret key here?
The key is used only inside your browser and is not transmitted or stored. Even so, treat production secrets with care: prefer test keys, and rotate a key if you pasted it somewhere you do not fully trust.
Why does my HMAC not match the service's?
Check that the message is byte for byte identical, including line endings and encoding (UTF-8), that you use the same key with no extra spaces, and that you compare the same output format, hexadecimal or Base64.
Is this converter free?
Yes. There is no sign-up and no limit, and it runs in your browser, so nothing you type is sent to a server.
Does it work on a phone?
Yes. It works in any modern mobile browser, and the result updates as you type.