How to generate an HMAC signature
Create HMAC-SHA-256 (or SHA-384/SHA-512) signatures in your browser for webhooks and APIs.
HMAC vs a plain hash
A SHA hash only digests the message. HMAC also uses a secret key, which is what webhook providers expect when they say “sign the payload”.
Steps
1) Open HMAC Generator. 2) Enter the message as text, hex, Base64, or a file. 3) Enter the secret (text, hex, or Base64). Generate random fills a throwaway hex key for experiments — do not ship it. 4) Choose SHA256 (typical). SHA1 is weak; SHA384 and SHA512 are longer. The HMAC hex updates as you type — there is no Generate button on the article page. The All Algorithms table signs the same input with every option. The secret is not persisted.
Worked example and limits
A webhook that says “HMAC-SHA-256 of the raw body with your signing secret, hex lowercase” is this page: paste the exact bytes (watch trailing newlines), paste the secret, copy SHA256. HMAC is not encryption and not bcrypt. JWT Encoder wraps HMAC in a three-part token. Hash Generator is the sibling when you have no key. SHA1 is legacy. File mode hashes the file bytes, not the filename. Nothing is uploaded. Close the tab to drop the secret. Related: /tools/hash-generator, /tools/jwt-encoder, /tools/bcrypt-hash.