My Tool Studio
Developer

HMAC Generator

This HMAC generator creates keyed hashes with SHA-256, SHA-1, SHA-384, SHA-512, SHA3-256, SHA3-512 or MD5, the signatures that webhooks and APIs use to prove a message is genuine. Enter the secret key and the message, and the HMAC updates as you type. Keys and messages can be text, hex or Base64, and the message can also be a file up to 200 MB. Choose hex, uppercase hex, Base64 or Base64URL output to match the header you are checking, or tick Show every algorithm to see them all at once. Paste a received signature into Verify and the tool tells you whether it matches, ignoring prefixes like sha256=. Everything runs in your browser, so keys stay private.

Always freeNo sign upRuns in your browser

How to use

01

Enter the key

Type or paste the shared secret into Secret key and set Key is to text, hex or Base64. Random 256-bit key creates a new secret if you are setting up signing yourself.

02

Add the message

Paste the exact message, such as a webhook's raw request body, or switch to the File tab and choose a file. Pick the Algorithm and Output format that your API documents.

03

Copy or verify

Copy the HMAC, or paste the signature you received into Verify a signature. A green notice means it matches; otherwise check the key, the exact bytes and the output format.

Why HMAC Generator

Worked example: signing a webhook body

Say a shop sends this body: {"id":"evt_1042","type":"order.paid","amount":4999}, signed with the secret my-webhook-secret. Try sample loads exactly these values. With HMAC-SHA256 and hex output the result is 0e16d51af3200994cbff80aa09e145f8477191a7c0eddf328c13ff99dad87f39, and in Base64 it is DhbVGvMgCZTL/4CqCeFF+EdxkafA7d8yjBP/mdrYfzk=.

Now add a single space after the first colon, as a JSON library might when it re-formats the body. The HMAC becomes 8e8c241c5d6985ba2a4d2ed69d8aba811832d5e23b915e963b1f3b936bfc8020, with no resemblance to the first. That is why webhook handlers must sign the raw body they received, never a parsed and re-serialized copy.

HMAC algorithms and where you meet them

All of these follow the same RFC 2104 recipe; only the hash inside changes. The output length is fixed by the hash, whatever the key or message length.

AlgorithmHex charactersCommon uses
HMAC-SHA25664Webhooks from GitHub, Stripe and Shopify, AWS Signature Version 4, JWT HS256
HMAC-SHA38496JWT HS384
HMAC-SHA512128JWT HS512, some exchange and payment APIs
HMAC-SHA140OAuth 1.0 signatures, TOTP one-time codes, older webhooks
HMAC-MD532Legacy systems and some older payment gateways
HMAC-SHA3-256 and SHA3-51264 and 128Newer designs that standardize on SHA-3

Computing the same HMAC in code

Once the values match here, the same call in your language should give the same result. Each line below signs body with key using SHA-256 and returns hex:

  • Node.js: crypto.createHmac('sha256', key).update(body).digest('hex')
  • Python: hmac.new(key.encode(), body.encode(), hashlib.sha256).hexdigest()
  • PHP: hash_hmac('sha256', $body, $key)
  • Go: h := hmac.New(sha256.New, []byte(key)); h.Write([]byte(body)); hex.EncodeToString(h.Sum(nil))
  • Shell: printf '%s' "$body" | openssl dgst -sha256 -hmac "$key"
  • Compare signatures with a constant-time function, such as crypto.timingSafeEqual or hmac.compare_digest, not ==.

Common questions

What is an HMAC and how is it different from a plain hash?
An HMAC mixes a secret key into the hash in a fixed way defined in RFC 2104. Anyone can compute a plain SHA-256 of a message, but only someone with the key can compute its HMAC, so a matching HMAC shows the sender knew the key and the message was not changed.
How do I verify a webhook signature with an HMAC generator?
Copy the raw request body exactly as received, before any JSON parsing, and paste it as the message. Enter the webhook signing secret as the key, choose the algorithm the provider documents, usually SHA-256, and paste the signature header into Verify. Some providers sign a timestamp plus the body, so follow their format exactly.
Why does my HMAC not match the one from my server?
The bytes differ somewhere. Common causes are a message that was re-formatted or had its line endings changed, a key that is Base64 or hex but was entered as text, a trailing newline, or comparing hex with Base64 output. Change one thing at a time until the values agree.
Should the HMAC key be text, hex or Base64?
Use whatever form your provider gives you, and tell the tool with Key is. A key shown as whsec_ or sk_ followed by letters is usually used as text. A 64-character value of 0-9 and a-f is often hex, and a value ending in = is usually Base64.
How long should an HMAC secret key be?
At least as long as the hash output: 32 bytes for HMAC-SHA256 and 64 bytes for HMAC-SHA512. RFC 2104 advises against keys shorter than the output length. Random 256-bit key creates a 32-byte key with the browser's secure random generator.
Is HMAC-SHA1 or HMAC-MD5 still safe to use?
No practical attacks on HMAC-SHA1 or HMAC-MD5 are known, because HMAC does not rely on collision resistance the way plain hashes do. They are kept for older APIs, such as OAuth 1.0 signatures and some payment gateways. Choose HMAC-SHA256 or stronger for anything new.
Which output format should I pick for an HMAC?
Match the signature you compare against. GitHub and Stripe send hex, Shopify sends Base64, and JWTs use Base64URL. The bytes are identical in every format; only the way they are written changes, so a hex value will never equal a Base64 one.
Can I compute an HMAC of a file?
Yes. Open the File tab and choose a file up to 200 MB. The file is read in your browser and its raw bytes are signed with the key, which is useful when an API signs uploads or when you need to prove a download came from someone who holds the key.
Does this HMAC generator send my secret key anywhere?
No. The HMAC is computed with the Web Crypto API, plus small built-in code for MD5 and SHA-3, inside your browser tab. Nothing you type or open is uploaded or stored, so you can test real signing keys, though rotating keys you have shared elsewhere is still wise.

More Developer tools

View all