BasicApps Logo
HMAC Generator

Generate HMAC (Hash-based Message Authentication Codes) using various hash algorithms

HMAC Generator

Characters: 57 | Bytes: 57
Security: Excellent - Industry standard

HMAC Result

Real-time HMAC generation will appear here

Recommended

SHA256:Industry Standard
SHA512:High Security
SHA3:Latest Standard

Legacy

SHA1:Deprecated
MD5:Avoid
Use only for backward compatibility

Use Cases

• API request authentication
• JWT token signing
• Webhook verification
• Data integrity checking
• Message authentication

HMAC Security Tips

  • • Strong Keys: Use cryptographically random keys with sufficient length
  • • Key Management: Store keys securely, rotate regularly, never hardcode
  • • Algorithm Choice: Use SHA-256 or SHA-512 for new applications
  • • Constant-Time Comparison: Always use constant-time comparison for verification
  • • Include Timestamps: Add timestamps to prevent replay attacks

You need a message, a secret key, and an algorithm — that's the whole input

HMAC is what you reach for when a plain hash isn't enough. A plain SHA-256 of your payload proves the data, but anyone can recompute it since there's no secret involved. HMAC-SHA256 with a secret key means only someone who has your key can produce a valid signature — which is why it shows up constantly in webhook verification, API request signing, and JWT tokens. The typical flow here: paste your payload in the message field, paste your API secret in the key field, pick HMAC-SHA256, and copy the hex output. That hex value is what you'd put in an X-Signature header or compare against the value a service sends you. SHA-256 is the right default. SHA-512 if you're matching an existing system that requires it.

The output format matters depending on what's consuming it

Hex is the safe choice — lowercase hex works everywhere, it's what Stripe, GitHub, and most services use. Base64 is more compact and shows up in JWT signatures and some older HMAC APIs. If you're comparing two signatures and they don't match, check encoding first before assuming the keys differ. One common mistake is including the sha256= prefix in the comparison rather than just the hex part — some webhook specs include that prefix in the signature header as a type indicator, not as part of the actual HMAC value. Compare the values after that prefix or comparison will always fail even with correct keys.