DevToolPal
EN

HMAC Generator

Calculate HMAC-MD5, HMAC-SHA1, HMAC-SHA256, HMAC-SHA384 and HMAC-SHA512 of a message with a secret key, in hex or Base64.

Runs locally, never uploaded

Options

Key format
Output

Message

0 chars · 0 B

HMAC

Result appears here

What it does

HMAC (Hash-based Message Authentication Code, RFC 2104) combines a secret key with a hash function to sign a message. The receiver, who knows the same key, recomputes the HMAC and compares it with the one sent along. If anything in the message was changed, or the sender did not know the key, the values do not match.

HMACs are everywhere: webhook signatures (GitHub, Stripe, Slack), signed API requests, JWTs with the HS256 algorithm, cookie signing and one-time password codes. This tool calculates HMAC-MD5, HMAC-SHA1, HMAC-SHA256, HMAC-SHA384 and HMAC-SHA512 at the same time, so you can compare against whichever one your system uses.

How to use

  1. Type the Secret key. Choose Key format if your key is given as hex or Base64 bytes instead of plain text.
  2. Paste the Message, or click Sample.
  3. Every HMAC updates as you type. Choose Hex or Base64 output and copy the value you need.

The message is encoded as UTF-8, exactly as typed, including spaces and line breaks.

Example

With the key key and the message The quick brown fox jumps over the lazy dog, HMAC-SHA256 is f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8. You can check the same value on the command line:

echo -n "The quick brown fox jumps over the lazy dog" | openssl dgst -sha256 -hmac "key"

Note the -n: without it, echo adds a newline and the HMAC is different.

Verifying webhooks

To verify a webhook, take the raw request body before any JSON parsing, build the string the provider documents (often timestamp.body), compute the HMAC with your signing secret and compare it with the signature header. In your own code, compare signatures with a constant-time function to avoid timing attacks.

FAQ

› What is the difference between a hash and an HMAC?

A plain hash such as SHA-256 can be computed by anyone. An HMAC mixes a secret key into the hash, so only someone who knows the key can produce or check the value. That makes it a message authentication code, not just a checksum.

› Which HMAC algorithm should I use?

HMAC-SHA256 is the usual choice and is what most APIs and webhooks expect. HMAC-SHA512 is fine too. HMAC-MD5 and HMAC-SHA1 are still considered secure as MACs, but use them only when an older system requires them.

› Why does my HMAC not match the one from my server?

Check the exact message bytes (a trailing newline or different JSON spacing changes everything), the key format (text versus hex or Base64), and the output encoding. Webhook providers often sign a string built from a timestamp and the raw request body.

› Is my secret key stored or sent anywhere?

No. The HMAC is calculated in your browser. The key is kept only in memory on this page; it is not saved, not written to the address bar and not included in share links.