HMAC Generator
Generate HMAC-SHA1, SHA256, SHA512 online
Paste the message and secret first, then generate the HMAC; algorithm comparisons and edge cases are available in Advanced mode.
The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
Compute HMAC-SHA1, HMAC-SHA256 and HMAC-SHA512 from a UTF-8 message and UTF-8 text key with Web Crypto. Results are lowercase hexadecimal strings. Messages and keys stay in memory; this page does not save a secret draft or assemble a service-specific webhook signing string.
Production Snippets
A stable HMAC-SHA256 test vector
text
Key: key
Message: The quick brown fox jumps over the lazy dog
HMAC-SHA256:
f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8Suggested Workflow
Frequently Asked Questions
Does HMAC encrypt the message?
No. It authenticates a message using a shared key and does not conceal the content. Verification also needs the same key and exact bytes; a plain hash does not provide the same shared-key authentication.
Which algorithms and output encoding are supported?
The choices are SHA-1, SHA-256 and SHA-512 inside HMAC, with 40, 64 and 128 lowercase hex characters. MD5, SHA-384, Base64 output and automatic hex/Base64 key decoding are not available.
Why does a webhook signature differ?
Check the exact message, whitespace, line endings, UTF-8 encoding, key bytes and output format. A timestamp, HTTP method or raw request body may be part of the provider’s signing string; this page does not add them for you.
Can I sign an empty message or use a blank key?
This interface requires a non-whitespace message and a nonempty key. It signs the original message without trimming it. These are interface restrictions, not mathematical restrictions of HMAC.
How should I choose an algorithm and handle secrets?
Follow the protocol you are testing rather than choosing by digest length alone. New designs commonly use HMAC-SHA256. Use synthetic test keys here; generation is local, old plaintext drafts are removed, and new messages or keys are not persisted.
Keep browsing