HMAC Generator
Create and verify HMAC signatures for APIs and webhooks. Enter a secret key (text, hex or Base64) and a message, choose the hash, and get the signature in hex or Base64 — then paste a signature you received to check it matches.
Choose the hash function (HMAC-SHA256 is the most common), enter the secret key and its format, and paste the exact message. The HMAC updates instantly in hex or Base64. Paste a received signature to verify it — prefixes like sha256= are handled. The key never leaves your browser.
HMAC-SHA-256
b613679a0814d9ec772f95d778c35fc5ff1697c493715653c6c712144292c5ad
Zero Server Uploads
Files process in local RAM
Instant WASM Speed
No waiting queues or lags
Unlimited Batching
Convert files without limits
Suggest a Feature or Improvement for HMAC Generator
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use HMAC Generator
- 1Choose the hash function (usually SHA-256).
- 2Enter the secret key and pick its format.
- 3Paste the exact message or request body.
- 4Copy the signature, or paste one to verify.
What HMAC does
HMAC (RFC 2104) combines a secret key with a hash function to produce a signature that proves two things: the message came from someone who knows the key, and it wasn't modified. APIs like AWS Signature v4 and webhooks from GitHub, Stripe and Shopify use HMAC-SHA256.
Unlike a plain hash, an attacker can't recompute an HMAC without the key, and unlike public-key signatures it's symmetric: both sides share the same secret.
Getting matching signatures
Most mismatches come from the input, not the algorithm: sign the raw bytes exactly as received (don't re-serialise JSON), check whether the key is text or hex/Base64-decoded, and compare the same encoding. For provider-specific formats use the Webhook Signature Generator.
Frequently Asked Questions
Is HMAC-SHA1 still secure?
Yes — HMAC's security doesn't depend on the collision resistance that broke SHA-1. Still, prefer HMAC-SHA256 for new systems.
How long should the HMAC key be?
At least as long as the hash output: 32 random bytes for HMAC-SHA256. Generate one with the Secure Token Generator.
Is my data sent to your server?
No. This tool runs entirely in your browser using the Web Crypto API and JavaScript. Nothing you type or generate is uploaded, logged or stored.
Related Tools
Webhook Signature Generator
Generate and verify webhook signatures for GitHub, Stripe, Slack, Shopify, Standard Webhooks and Twilio.
SHA-256 Hash Generator
Generate SHA-256 hashes of text or files instantly — hex or Base64, with checksum comparison.
Secure Token Generator
Generate cryptographically secure random tokens and secrets in hex, Base64url, Base62 or Base32.