HMAC

HMAC Generator

Generate HMAC-SHA1, SHA256, SHA512 online

Security & Auth
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 29, 2026
Options
Input

Paste the message and secret first, then generate the HMAC; algorithm comparisons and edge cases are available in Advanced mode.

Algorithms
🔒 Processed locally in your browser · Web Crypto API
Output
Enter a message and secret key to generate HMAC
Page reading mode

The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.

About this tool

Compute HMAC-SHA1, HMAC-SHA256 and HMAC-SHA512 from a UTF-8 message and UTF-8 text key with Web Crypto. Results are lowercase hexadecimal strings. Messages and keys stay in memory; this page does not save a secret draft or assemble a service-specific webhook signing string.

Production Snippets

A stable HMAC-SHA256 test vector

text

Key: key
Message: The quick brown fox jumps over the lazy dog
HMAC-SHA256:
f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8

Suggested Workflow

Frequently Asked Questions

Does HMAC encrypt the message?

No. It authenticates a message using a shared key and does not conceal the content. Verification also needs the same key and exact bytes; a plain hash does not provide the same shared-key authentication.

Which algorithms and output encoding are supported?

The choices are SHA-1, SHA-256 and SHA-512 inside HMAC, with 40, 64 and 128 lowercase hex characters. MD5, SHA-384, Base64 output and automatic hex/Base64 key decoding are not available.

Why does a webhook signature differ?

Check the exact message, whitespace, line endings, UTF-8 encoding, key bytes and output format. A timestamp, HTTP method or raw request body may be part of the provider’s signing string; this page does not add them for you.

Can I sign an empty message or use a blank key?

This interface requires a non-whitespace message and a nonempty key. It signs the original message without trimming it. These are interface restrictions, not mathematical restrictions of HMAC.

How should I choose an algorithm and handle secrets?

Follow the protocol you are testing rather than choosing by digest length alone. New designs commonly use HMAC-SHA256. Use synthetic test keys here; generation is local, old plaintext drafts are removed, and new messages or keys are not persisted.

Keep browsing