HMAC Generator

HMAC Generator

Generate HMAC (Hash-based Message Authentication Code) using various algorithms. HMAC is commonly used to verify the integrity and authenticity of messages.

Free
No signup
Instant
Private

1. Enter your data

43 characters

2. Enter your key

3. Select algorithm

SHA256 is a strong general-purpose algorithm.

4. HMAC Result

SHA256

e8597b12deabbf388d9d0c6c14e1f9c739333252033ee7cbb59eeaa166cb0e2c
64 characters
Strong

All Algorithms

AlgorithmHMAC (Hex)LengthActions
SHA1d62f05da139a44493781b05380b1816b6aac0df940
SHA256e8597b12deabbf388d9d0c6c14e1f9c739333252033ee7cbb59eeaa166cb0e2c64
SHA384e92cd1f19aa6431b269151d95e3da8413d18f1d78ffe7a8f4ebb82609bffbe8c9363ccb2cb7a68f691df0c10f3fa82a496
SHA512e3ffe852f556119f4e5df9fa71460f69a6868953981cd5699e0055c423bd531ae34abf2d40551dba3f1ce1e64e9a484801fc6c3539ba0c55499b8dd3d1218bd4128

About HMAC

HMAC (Hash-based Message Authentication Code) combines a cryptographic hash with a secret key so a receiver can check both integrity and authenticity. A plain SHA-256 digest only fingerprints the bytes; anyone can recompute it. HMAC answers “did someone who knew this key produce this hex?” Webhook providers (Stripe, GitHub, Slack) document HMAC-SHA-256 over the raw body. This page signs in Web Crypto: SHA-1, SHA-256, SHA-384, SHA-512. There is no MD5 and no SHA-224. The hex updates as you type. The All Algorithms table signs the same input with every option so you can copy the digest a vendor named without re-pasting. Message and key encodings are independent: text, hex, or Base64, and the message may be a file read locally. Invalid hex (odd length) or Base64 is rejected before signing. Generate random fills a hex key for experiments — do not use that throwaway as a production secret. Show key reveals the field; we still do not persist the secret. SHA-1 is weak; keep it only when a legacy API demands it. HMAC is not encryption and not a password hash. Do not HMAC a password to store it — use bcrypt. Do not treat HMAC hex as a JWT; JWT Encoder wraps HMAC in a three-part token. Hash Generator is the sibling when you have no key. Nothing is uploaded. Close the tab to drop the message and key from memory.

Your data stays private

Everything is processed locally in your browser. We never upload or store your data.

Learn more about privacy →

Common use cases

API Authentication

Sign and verify API requests with a shared secret.

Webhooks

Confirm that incoming payloads are genuine.

File Integrity

Detect tampering when a file is transferred.

Data Security

Protect sensitive payloads with a keyed digest.

Message Signing

Verify the sender’s authenticity.

Enter the message

Paste text, hex, Base64, or choose a file. A character or byte count appears under the field.

Enter the key

Use a text, hex, or Base64 secret. Generate random fills a hex key. Show key reveals the field.

Choose an algorithm

SHA256 is the usual choice. SHA1 is weak. SHA384 and SHA512 are stronger.

Copy the HMAC

Copy, download, or share the hex digest. The HMAC updates as you type. Nothing is uploaded.

Related developer tools

HMAC Generator FAQ

Enter the message as text, hex, Base64, or a file, then the secret key, and choose SHA256 (or SHA1, SHA384, SHA512). The HMAC hex updates as you type. The All Algorithms table signs the same input with every option.

No. HMAC uses a secret key plus the message. Use Hash Generator when you only need a digest without a key.

No. HMAC runs locally in this browser. Messages and keys are never sent to Toolora servers.