HMAC Generator
Create an HMAC-SHA-256 signature locally with a message and secret key.
Create an HMAC-SHA-256 signature locally with a message and secret key.
A regular hash like MD5 or SHA-256 answers one question: "does this data match a known digest?" Anyone can compute a hash, so it can't prove who produced a message. HMAC (Hash-based Message Authentication Code), defined in RFC 2104, fixes that by mixing a secret key into the hash computation using a construction that pads and combines the key with the message in two nested hash passes. The result — the HMAC — can only be reproduced by someone who also knows the secret key, which is what makes it useful for verifying both the integrity and the origin of a message.
This tool generates HMAC-SHA-256 specifically, computed with the browser's built-in crypto.subtle.sign() Web Crypto API call rather than a JavaScript reimplementation. SHA-256 is currently the most common hash paired with HMAC and is considered secure for this purpose.
HS256 algorithm is, under the hood, an HMAC-SHA-256 signature over the token's header and payload.HMAC mixes a secret key into the hash so only someone who knows the key can produce or verify a valid signature. A plain hash alone proves nothing about who created the data, since anyone can compute it.
HMAC-SHA-256, computed with the browser's native Web Crypto API. It's the most common HMAC variant in modern use and is considered secure for message authentication.
Verifying webhook payloads (Stripe, GitHub), signing API requests (AWS Signature V4), and as the integrity check inside JWT tokens signed with the HS256 algorithm.
No. The signature is computed entirely inside your browser via the Web Crypto API — the message and key never leave the page.