Cryptography Tools

HMAC Generator

Create an HMAC tag for a message using a secret key and SHA-256, SHA-384, or SHA-512. The key and message stay in this browser.

✓ Every tool runs in your browser. We do not upload your input or output.

HMAC Generator
Keyboard shortcuts

Ctrl/⌘ + Enter: process

Ctrl/⌘ + Shift + F: full screen

Esc: exit full screen

Ctrl/⌘ + F in editor: search

HMAC hex digest
ReadyLines: 1 · Characters: 0 · Size: 0 KB · Time: — · Cursor: 1:1

How to use

  1. Enter the exact message in the editor.
  2. Type a secret key in the password field and select a SHA-2 algorithm.
  3. Run the tool and copy the hexadecimal tag.
  4. Use the same message bytes, key, and algorithm when verifying the tag elsewhere.

Examples

Sign a webhook test message

Both systems must agree on exact bytes; a different field order changes the tag.

Input
order_id=7812&amount=24.50
Output
A hexadecimal HMAC tag

Verify the exact bytes

HMAC is useful when a webhook sender and receiver share a secret. Each side calculates a tag over the same message, then compares tags. This tool helps you reproduce a sample signature while testing integrations. It uses the browser’s Web Crypto HMAC implementation and presents the result in lowercase hex. The selected digest changes both output length and signature value.

The password field is only a local input control. Your secret is passed to a Web Worker in the same browser tab for processing and is not transmitted to this site’s server. Clear the field or close the tab when finished. For production signature checks, compare tags using the security guidance for your platform and read the provider’s exact signing specification. HMAC does not encrypt the payload, and signing a reserialized JSON object may differ from signing the original raw request body.

Frequently asked questions

Is HMAC the same as a hash?

HMAC includes a secret key. A plain SHA digest does not authenticate a message.

Is the message encrypted?

No. HMAC checks authenticity and integrity but does not hide the message.

Can I reuse a weak key?

Use a strong, randomly generated key and store it securely in your application.

Why does a webhook signature differ?

Check the raw request body, encoding, selected algorithm, and whether the provider uses hex or Base64.

Related tools