HMAC Generator
Sign a message with a secret key, or check a webhook signature you were sent.
Runs entirely in your browser
Loading tool...
How to use
- Paste the message exactly as it was signed — for a webhook, the raw body before any parsing.
- Enter the shared secret.
- Pick the algorithm the sender used; SHA-256 unless their documentation says otherwise.
- To verify, paste the signature you received and read the comparison.
Features
- HMAC with SHA-1, SHA-256, SHA-384 and SHA-512, from Web Crypto.
- Hex or base64 output, which is where two implementations usually disagree.
- Verification with a constant-time comparison.
- An empty key is refused rather than signed with.
- Runs entirely in your browser — the secret never leaves the page.
Frequently asked questions
- Why not just hash the secret and the message together?
- Because `hash(secret + message)` is forgeable. With most hash functions an attacker who has one valid signature can append data and compute a valid signature for the longer message without ever knowing the secret — a length extension attack. HMAC is the construction designed to prevent exactly that, which is why signing schemes specify it instead of the obvious thing.
- My signature does not match. What is wrong?
- Almost always the message, not the key. Signatures are computed over exact bytes: a framework that parsed and re-serialised the JSON body has already changed them, and so has a trailing newline, a different key order, or the wrong encoding. Some schemes also sign a timestamp and the body together — check what the sender's documentation says is signed, and reproduce it exactly.
- Is it safe to paste a production secret here?
- It never leaves your browser — there is no server and no request. That said, treat any secret pasted into any tool as one you may need to rotate: a browser extension can read this page like any other. For a one-off check on a webhook, the risk is low; for a routine part of your work, sign in your own code.
Related tools
Check that the two-factor secret you saved really produces the code on your phone — before the phone is gone.
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes, or verify a checksum.
Read the header, claims and expiry of a JSON Web Token — without sending it anywhere.
What kind of hash is this? A ranked shortlist, and an honest note about when the answer cannot be known.