HMAC Generator

Create an HMAC signature for a message or file with a secret key, using SHA-1, SHA-256, SHA-384, or SHA-512. Paste an expected signature to check that it matches.

Updated
Signed in your browser. Your message and key are not uploaded.

Signed as UTF-8. A trailing space or line break changes the result.

Signs as you type.

How to use the HMAC Generator

  1. Type the Message, or open the File tab and choose a file.
  2. Enter the Secret key and pick its Key format, then choose the Algorithm and Output.
  3. Copy the signature. To check a webhook or API signature, paste the value you received into Compare with.

How it works

HMAC (hash-based message authentication code, RFC 2104) mixes a secret key into a hash of the message:

HMAC(K, m) = H((K′ ⊕ opad) ‖ H((K′ ⊕ ipad) ‖ m))
  • H is the hash function, for example SHA-256.
  • K′ is the key padded to the hash's block size (64 bytes for SHA-256), or hashed first if it is longer.
  • ipad and opad are the bytes 0x36 and 0x5C repeated.

Only someone with the same key can produce the same signature, so the receiver can tell the message wasn't changed and came from a key holder. The calculation uses your browser's Web Crypto API; text is signed as UTF-8 bytes.

Examples

  • Key key, message The quick brown fox jumps over the lazy dog, HMAC-SHA256 = f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8.
  • The same message with the key Key (capital K) gives a completely different signature, which is why keys must match exactly.
  • Webhook providers such as GitHub and Stripe send an HMAC-SHA256 of the raw request body. Sign the exact body you received, not a reformatted copy.

HMAC algorithms compared

AlgorithmSignature lengthHex charactersUse
HMAC-SHA1160 bits40Older APIs, TOTP codes
HMAC-SHA256256 bits64The default for webhooks, JWT (HS256), AWS SigV4
HMAC-SHA384384 bits96JWT HS384
HMAC-SHA512512 bits128JWT HS512, high-security settings

Limitations

  • HMAC-MD5 is not offered, because Web Crypto doesn't support it.
  • Files are limited to 50 MB, and the whole file is read into memory.
  • A trailing line break in the message or the key changes the result. It's the most common reason a signature doesn't match.
  • Comparing signatures here is for checking by hand. In your own code, use a constant-time comparison such as hash_equals or crypto.timingSafeEqual.

Frequently asked questions

What is the difference between a hash and an HMAC?

A hash can be computed by anyone. An HMAC also needs a secret key, so it proves that whoever made it knew the key.

Is HMAC-SHA1 still safe?

Yes for HMAC. The known SHA-1 collision attacks don't break HMAC-SHA1. For new systems, HMAC-SHA256 is still the better choice.

Why doesn't my webhook signature match?

Usually the body was changed before signing, for example parsed and re-serialized as JSON, or the key has extra spaces. Sign the raw body bytes with the exact secret.

Is my key sent to your server?

No. The signature is calculated in your browser with Web Crypto, and the key and message stay on your device.

Often used together with the HMAC Generator.

  • Hash Generator

    Computes checksums of text or files and compares them with an expected hash.

  • JWT Decoder

    Decodes JSON Web Tokens, explains the claims, and verifies HS, RS, PS, and ES signatures.