Generate HMAC (Hash-based Message Authentication Codes) using various hash algorithms
HMAC Generator
Generate HMAC (Hash-based Message Authentication Codes) using various hash algorithms
HMAC Generator
HMAC Result
Recommended
Legacy
Use Cases
HMAC Security Tips
- • Strong Keys: Use cryptographically random keys with sufficient length
- • Key Management: Store keys securely, rotate regularly, never hardcode
- • Algorithm Choice: Use SHA-256 or SHA-512 for new applications
- • Constant-Time Comparison: Always use constant-time comparison for verification
- • Include Timestamps: Add timestamps to prevent replay attacks
You need a message, a secret key, and an algorithm — that's the whole input
HMAC is what you reach for when a plain hash isn't enough. A plain SHA-256 of your payload proves the data, but anyone can recompute it since there's no secret involved. HMAC-SHA256 with a secret key means only someone who has your key can produce a valid signature — which is why it shows up constantly in webhook verification, API request signing, and JWT tokens. The typical flow here: paste your payload in the message field, paste your API secret in the key field, pick HMAC-SHA256, and copy the hex output. That hex value is what you'd put in an X-Signature header or compare against the value a service sends you. SHA-256 is the right default. SHA-512 if you're matching an existing system that requires it.
The output format matters depending on what's consuming it
Hex is the safe choice — lowercase hex works everywhere, it's what Stripe, GitHub, and most services use. Base64 is more compact and shows up in JWT signatures and some older HMAC APIs. If you're comparing two signatures and they don't match, check encoding first before assuming the keys differ. One common mistake is including the sha256= prefix in the comparison rather than just the hex part — some webhook specs include that prefix in the signature header as a type indicator, not as part of the actual HMAC value. Compare the values after that prefix or comparison will always fail even with correct keys.
