Cryptography Tools
HMAC Generator
Create an HMAC tag for a message using a secret key and SHA-256, SHA-384, or SHA-512. The key and message stay in this browser.
✓ Every tool runs in your browser. We do not upload your input or output.
Keyboard shortcuts
Ctrl/⌘ + Enter: process
Ctrl/⌘ + Shift + F: full screen
Esc: exit full screen
Ctrl/⌘ + F in editor: search
How to use
- Enter the exact message in the editor.
- Type a secret key in the password field and select a SHA-2 algorithm.
- Run the tool and copy the hexadecimal tag.
- Use the same message bytes, key, and algorithm when verifying the tag elsewhere.
Examples
Sign a webhook test message
Both systems must agree on exact bytes; a different field order changes the tag.
order_id=7812&amount=24.50
A hexadecimal HMAC tag
Verify the exact bytes
HMAC is useful when a webhook sender and receiver share a secret. Each side calculates a tag over the same message, then compares tags. This tool helps you reproduce a sample signature while testing integrations. It uses the browser’s Web Crypto HMAC implementation and presents the result in lowercase hex. The selected digest changes both output length and signature value.
The password field is only a local input control. Your secret is passed to a Web Worker in the same browser tab for processing and is not transmitted to this site’s server. Clear the field or close the tab when finished. For production signature checks, compare tags using the security guidance for your platform and read the provider’s exact signing specification. HMAC does not encrypt the payload, and signing a reserialized JSON object may differ from signing the original raw request body.
Frequently asked questions
Is HMAC the same as a hash?
HMAC includes a secret key. A plain SHA digest does not authenticate a message.
Is the message encrypted?
No. HMAC checks authenticity and integrity but does not hide the message.
Can I reuse a weak key?
Use a strong, randomly generated key and store it securely in your application.
Why does a webhook signature differ?
Check the raw request body, encoding, selected algorithm, and whether the provider uses hex or Base64.