HMAC Generator

Create an HMAC-SHA-256 signature locally with a message and secret key.

What HMAC does that a plain hash can't

A regular hash like MD5 or SHA-256 answers one question: "does this data match a known digest?" Anyone can compute a hash, so it can't prove who produced a message. HMAC (Hash-based Message Authentication Code), defined in RFC 2104, fixes that by mixing a secret key into the hash computation using a construction that pads and combines the key with the message in two nested hash passes. The result — the HMAC — can only be reproduced by someone who also knows the secret key, which is what makes it useful for verifying both the integrity and the origin of a message.

This tool generates HMAC-SHA-256 specifically, computed with the browser's built-in crypto.subtle.sign() Web Crypto API call rather than a JavaScript reimplementation. SHA-256 is currently the most common hash paired with HMAC and is considered secure for this purpose.

Where you'll run into HMAC

How to use it

  1. Type or paste the message you want to sign.
  2. Enter the shared secret key.
  3. Click Generate HMAC to compute the signature locally, then copy it to compare against a value from your server or API provider.

Common questions

What is HMAC and how is it different from a plain hash?

HMAC mixes a secret key into the hash so only someone who knows the key can produce or verify a valid signature. A plain hash alone proves nothing about who created the data, since anyone can compute it.

Which hash function does this generator use?

HMAC-SHA-256, computed with the browser's native Web Crypto API. It's the most common HMAC variant in modern use and is considered secure for message authentication.

Where is HMAC used in practice?

Verifying webhook payloads (Stripe, GitHub), signing API requests (AWS Signature V4), and as the integrity check inside JWT tokens signed with the HS256 algorithm.

Is my secret key sent anywhere?

No. The signature is computed entirely inside your browser via the Web Crypto API — the message and key never leave the page.