Online HMAC Generator (SHA-256, SHA-1…)

Compute an HMAC hash (with a secret key) to sign or verify a message. Choose the algorithm, enter the message and the key: the result is instant and local.

HMAC hash

—

100% local processing, nothing is uploaded

How does it work?

HMAC (RFC 2104) combines a message and a secret key to produce a hash that only someone who knows the key can recompute. It guarantees both the integrity and the authenticity of a message: an API uses it to check that a request really comes from its partner, a webhook to prove it has not been forged.

Choose the underlying algorithm (HMAC-SHA256 is the most common), enter the message and the key (as text or hexadecimal), and the hash appears. Everything is computed locally.

Examples

Signing a webhook

A service signs each webhook with HMAC-SHA256 and a shared key. The recipient recomputes the hash of the received body with the same key: if it matches the signature header, the message is authentic and intact.

RFC 4231 test vector

HMAC-SHA256 with the key 0x0b… (20 bytes) and the message “Hi There” gives b0344c61d8db3853…2e32cff7, the reference value from RFC 4231.

Frequently asked questions

What is the difference between HMAC and a simple “key + message” hash?
HMAC applies the hash function twice with paddings derived from the key. This construction resists attacks (length extension) to which a simple SHA-256(key || message) would be vulnerable.
Which algorithm should I choose?
HMAC-SHA256 is the default choice, secure and universally supported. HMAC-SHA512 offers a larger margin. Avoid HMAC-MD5 and HMAC-SHA1 for any new use.
Is my data sent anywhere?
No. All the computation happens in your browser, in JavaScript and WebAssembly. Your text, your files and your hashes never leave your device: no network request is made during hashing, and nothing is stored on a server.