Skip to content

HMAC Generator

Compute an HMAC with SHA-256, SHA-384 or SHA-512 using the browser's Web Crypto implementation.

HMAC Generator

Hash-based Message Authentication Code calculator using Web Crypto API.

What HMAC Generator does

An HMAC is a hash combined with a secret key. Anyone can compute a plain hash of a message, so a plain hash proves nothing about who produced it. An HMAC can only be produced or verified by someone holding the key.

This is the mechanism behind signed webhooks and API request signing: the sender computes an HMAC over the payload, and the receiver recomputes it with the shared secret to confirm both the origin and that nothing was altered in transit.

  • HMAC-SHA256, HMAC-SHA384 and HMAC-SHA512
  • Uses the browser's Web Crypto implementation rather than a JavaScript reimplementation
  • Hexadecimal output, recomputed as you type
  • Secret field masked by default

How to use HMAC Generator

  1. 1

    Paste the message

    For webhook verification this is the exact raw request body, byte for byte, before any parsing or re-serialising.

  2. 2

    Enter the shared secret

    Use the same secret the sender used. The field is masked; reveal it if you need to check for a stray space.

  3. 3

    Pick the algorithm

    Match whatever the provider specifies. SHA-256 is the most common.

  4. 4

    Compare the signature

    Compare the result with the signature header you received. They must match exactly.

When to use it

Debugging webhook verification

When signature checks fail, computing the expected value by hand shows whether the problem is the secret, the algorithm or the payload.

Signing an API request

Some APIs require a signature over a canonical string; you can reproduce it here to check your implementation.

Limits and known behaviour

  • Web Crypto is only available in a secure context, so the tool requires HTTPS.
  • The message is treated as UTF-8 text. A payload containing raw binary cannot be reproduced faithfully by pasting it.
  • Webhook mismatches are most often caused by re-serialising the JSON body before hashing; the signature covers the exact bytes received, including whitespace and key order.
  • Only HMAC is offered. RSA and ECDSA signatures use a different mechanism with a key pair.

Privacy and data handling

Runs entirely in your browser

  • The message and the secret are used by the browser's own crypto implementation in this page and are never transmitted.
  • The key is imported as non-extractable and is discarded when the page is closed.

Site-wide data handling, including analytics and advertising, is described in the privacy policy.

Frequently asked questions

Why does my computed signature not match the provider's?

In order of likelihood: the body was parsed and re-serialised before hashing, so the bytes differ; the wrong secret was used; the provider signs a canonical string that includes a timestamp or the URL as well as the body; or the encoding is expected in base64 rather than hexadecimal.

How is this different from a plain hash?

A plain hash can be computed by anyone, so it only detects accidental change. An HMAC requires the secret, so it also establishes that the message came from someone who holds it.