Skip to content
Toolbench

HMAC Generator

Sign a message with a secret key, or check a webhook signature you were sent.

Runs entirely in your browser

Loading tool...

How to use

  1. Paste the message exactly as it was signed — for a webhook, the raw body before any parsing.
  2. Enter the shared secret.
  3. Pick the algorithm the sender used; SHA-256 unless their documentation says otherwise.
  4. To verify, paste the signature you received and read the comparison.

Features

  • HMAC with SHA-1, SHA-256, SHA-384 and SHA-512, from Web Crypto.
  • Hex or base64 output, which is where two implementations usually disagree.
  • Verification with a constant-time comparison.
  • An empty key is refused rather than signed with.
  • Runs entirely in your browser — the secret never leaves the page.

Frequently asked questions

Why not just hash the secret and the message together?
Because `hash(secret + message)` is forgeable. With most hash functions an attacker who has one valid signature can append data and compute a valid signature for the longer message without ever knowing the secret — a length extension attack. HMAC is the construction designed to prevent exactly that, which is why signing schemes specify it instead of the obvious thing.
My signature does not match. What is wrong?
Almost always the message, not the key. Signatures are computed over exact bytes: a framework that parsed and re-serialised the JSON body has already changed them, and so has a trailing newline, a different key order, or the wrong encoding. Some schemes also sign a timestamp and the body together — check what the sender's documentation says is signed, and reproduce it exactly.
Is it safe to paste a production secret here?
It never leaves your browser — there is no server and no request. That said, treat any secret pasted into any tool as one you may need to rotate: a browser extension can read this page like any other. For a one-off check on a webhook, the risk is low; for a routine part of your work, sign in your own code.

Check that the two-factor secret you saved really produces the code on your phone — before the phone is gone.

Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes, or verify a checksum.

Read the header, claims and expiry of a JSON Web Token — without sending it anywhere.

What kind of hash is this? A ranked shortlist, and an honest note about when the answer cannot be known.