DEV

HMAC Generator

Sign a message with a secret key using HMAC, or paste a signature to verify it. Supports SHA-256, SHA-512 and more, with text or hex keys.

MESSAGE
HMAC

          

How it works

An HMAC (hash-based message authentication code) mixes a secret key into a hash so only someone who knows the key can produce, or check, the result. The recipient recomputes the HMAC from the message and the shared secret; if it matches, the message is genuine and unchanged. It is the standard way to sign webhooks, API requests and cookies.

This tool follows RFC 2104: the key is padded to the hash's block size, combined with two fixed pads, and hashed twice around the message. Keys longer than the block size are hashed first. You can enter the key as plain text or as hex bytes when your service gives you a binary key.

Common reasons a signature doesn't match

Hidden whitespace is the usual culprit — a trailing newline in the body, or a different JSON spacing than the sender used. Sign the exact raw bytes that were sent, not a re-serialised version. Also confirm the algorithm (SHA-256 is the most common), whether the key is text or hex, and whether the sender used hex or Base64 output.

Treat real secrets with care. This page runs locally and sends nothing, but for production keys you should still prefer your own tooling. For a plain hash with no key, use the Hash Generator.

Frequently asked

Is my secret key sent anywhere?

No. The HMAC is computed in your browser with built-in Web Crypto and a local MD5 routine. Neither the key nor the message leaves your device.

What is the difference between a hash and an HMAC?

A plain hash can be computed by anyone, so it only detects accidental changes. An HMAC needs a secret key, so it also proves who produced it and resists deliberate tampering.

Which algorithm should I choose?

Match whatever the other side uses. If you are free to choose, pick SHA-256 or stronger. HMAC-MD5 and HMAC-SHA1 are not broken the way plain MD5 and SHA-1 are, but they are kept mainly for older systems.

Can I check a webhook signature with this?

Yes. Paste the exact raw request body as the message, enter the webhook secret as the key, choose the algorithm the provider documents, then paste the signature header value into the verify box. Remove any prefix such as sha256= first.