HMAC Generator
Generate HMAC (Hash-based Message Authentication Code) using various algorithms. HMAC is commonly used to verify the integrity and authenticity of messages.
1. Enter your data
2. Enter your key
3. Select algorithm
4. HMAC Result
SHA256
All Algorithms
| Algorithm | HMAC (Hex) | Length | Actions |
|---|---|---|---|
| SHA1 | d62f05da139a44493781b05380b1816b6aac0df9 | 40 | |
| SHA256 | e8597b12deabbf388d9d0c6c14e1f9c739333252033ee7cbb59eeaa166cb0e2c | 64 | |
| SHA384 | e92cd1f19aa6431b269151d95e3da8413d18f1d78ffe7a8f4ebb82609bffbe8c9363ccb2cb7a68f691df0c10f3fa82a4 | 96 | |
| SHA512 | e3ffe852f556119f4e5df9fa71460f69a6868953981cd5699e0055c423bd531ae34abf2d40551dba3f1ce1e64e9a484801fc6c3539ba0c55499b8dd3d1218bd4 | 128 |
About HMAC
HMAC (Hash-based Message Authentication Code) combines a cryptographic hash with a secret key so a receiver can check both integrity and authenticity. A plain SHA-256 digest only fingerprints the bytes; anyone can recompute it. HMAC answers “did someone who knew this key produce this hex?” Webhook providers (Stripe, GitHub, Slack) document HMAC-SHA-256 over the raw body. This page signs in Web Crypto: SHA-1, SHA-256, SHA-384, SHA-512. There is no MD5 and no SHA-224. The hex updates as you type. The All Algorithms table signs the same input with every option so you can copy the digest a vendor named without re-pasting. Message and key encodings are independent: text, hex, or Base64, and the message may be a file read locally. Invalid hex (odd length) or Base64 is rejected before signing. Generate random fills a hex key for experiments — do not use that throwaway as a production secret. Show key reveals the field; we still do not persist the secret. SHA-1 is weak; keep it only when a legacy API demands it. HMAC is not encryption and not a password hash. Do not HMAC a password to store it — use bcrypt. Do not treat HMAC hex as a JWT; JWT Encoder wraps HMAC in a three-part token. Hash Generator is the sibling when you have no key. Nothing is uploaded. Close the tab to drop the message and key from memory.
Your data stays private
Everything is processed locally in your browser. We never upload or store your data.
Common use cases
API Authentication
Sign and verify API requests with a shared secret.
Webhooks
Confirm that incoming payloads are genuine.
File Integrity
Detect tampering when a file is transferred.
Data Security
Protect sensitive payloads with a keyed digest.
Message Signing
Verify the sender’s authenticity.
Enter the message
Paste text, hex, Base64, or choose a file. A character or byte count appears under the field.
Enter the key
Use a text, hex, or Base64 secret. Generate random fills a hex key. Show key reveals the field.
Choose an algorithm
SHA256 is the usual choice. SHA1 is weak. SHA384 and SHA512 are stronger.
Copy the HMAC
Copy, download, or share the hex digest. The HMAC updates as you type. Nothing is uploaded.
Related developer tools
Hash Generator
Generate SHA-1, SHA-256, SHA-384, or SHA-512 hashes using various encodings. Hashing is commonly used to verify integrity and fingerprint data.
JWT Encoder
Sign an HS256, HS384, or HS512 JWT locally from a JSON payload and secret.
JWT Decoder
Decode a JWT header and payload in your browser as you type. The signature is displayed but not verified. Invalid tokens are not saved.
Bcrypt Hash / Verify
Hash a password with bcrypt, or verify a password against an existing hash — locally in your browser.
UUID Generator
Generate UUIDs instantly in your browser. Free, private, and no signup required.
HMAC Generator FAQ
Enter the message as text, hex, Base64, or a file, then the secret key, and choose SHA256 (or SHA1, SHA384, SHA512). The HMAC hex updates as you type. The All Algorithms table signs the same input with every option.
No. HMAC uses a secret key plus the message. Use Hash Generator when you only need a digest without a key.
No. HMAC runs locally in this browser. Messages and keys are never sent to Toolora servers.