Skip to content
FlexibleToolsAI
Security Toolkit · 100% Client-Side Private

HMAC Generator

Create and verify HMAC signatures for APIs and webhooks. Enter a secret key (text, hex or Base64) and a message, choose the hash, and get the signature in hex or Base64 — then paste a signature you received to check it matches.

Choose the hash function (HMAC-SHA256 is the most common), enter the secret key and its format, and paste the exact message. The HMAC updates instantly in hex or Base64. Paste a received signature to verify it — prefixes like sha256= are handled. The key never leaves your browser.

HMAC-SHA-256

b613679a0814d9ec772f95d778c35fc5ff1697c493715653c6c712144292c5ad

HMAC proves a message came from someone who knows the secret key and wasn't changed. The key never leaves your browser. For webhook formats (GitHub, Stripe, Slack, Shopify), use the Webhook Signature Generator.

Zero Server Uploads

Files process in local RAM

Instant WASM Speed

No waiting queues or lags

Unlimited Batching

Convert files without limits

Suggest a Feature or Improvement for HMAC Generator

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use HMAC Generator

  1. 1Choose the hash function (usually SHA-256).
  2. 2Enter the secret key and pick its format.
  3. 3Paste the exact message or request body.
  4. 4Copy the signature, or paste one to verify.

What HMAC does

HMAC (RFC 2104) combines a secret key with a hash function to produce a signature that proves two things: the message came from someone who knows the key, and it wasn't modified. APIs like AWS Signature v4 and webhooks from GitHub, Stripe and Shopify use HMAC-SHA256.

Unlike a plain hash, an attacker can't recompute an HMAC without the key, and unlike public-key signatures it's symmetric: both sides share the same secret.

Getting matching signatures

Most mismatches come from the input, not the algorithm: sign the raw bytes exactly as received (don't re-serialise JSON), check whether the key is text or hex/Base64-decoded, and compare the same encoding. For provider-specific formats use the Webhook Signature Generator.

Frequently Asked Questions

Is HMAC-SHA1 still secure?

Yes — HMAC's security doesn't depend on the collision resistance that broke SHA-1. Still, prefer HMAC-SHA256 for new systems.

How long should the HMAC key be?

At least as long as the hash output: 32 random bytes for HMAC-SHA256. Generate one with the Secure Token Generator.

Is my data sent to your server?

No. This tool runs entirely in your browser using the Web Crypto API and JavaScript. Nothing you type or generate is uploaded, logged or stored.

Related Tools