HMAC Generator
Keyed hashes for API and webhook signatures — compute, verify and get the code.
0 bytes
Secret key
HMAC
Hex, Base64 or Base64url, with or without a label such as sha256=. Compared in constant time.
All algorithms
Every algorithm for this message and key, in the chosen output format.
| Algorithm | HMAC | Copy |
|---|
Code: compute this HMAC in Node.js, Python, Ruby or the shell
Each snippet reads the key from the HMAC_KEY environment variable and the message from MESSAGE, so no secret is written into your code. They use the algorithm, key format, message format and output format chosen above.
About the HMAC Generator
An HMAC (hash-based message authentication code, RFC 2104 and FIPS 198-1) is a hash mixed with a secret key: only someone who has the key can produce the same value, so it proves that a message came from a key holder and was not changed. Webhooks, API request signatures, JWT HS256 tokens and one-time-password apps are all built on it.
This tool computes HMAC-SHA-256, SHA-384, SHA-512, SHA-224, SHA-1, SHA3-256, SHA3-512 and legacy HMAC-MD5 of text, hex or Base64 data — or of a file of any size — with the key given as text, hex or Base64, and shows the result in hex, Base64 or Base64url. Paste a signature you received to compare it in constant time; if it does not match, the tool tells you whether it matches another algorithm or encoding. Key-length advice follows RFC 2104, and Code shows the same calculation in Node.js, Python, Ruby and OpenSSL. Everything runs on your device.
How to use it
- Choose Text and type or paste the message exactly as it was signed (for a webhook, the raw request body), or choose File and drop a file.
- Enter the secret key and choose its format: Text for a passphrase-like secret, Hex or Base64 for raw key bytes.
- Pick the algorithm — HMAC-SHA-256 unless the service says otherwise — and the output format. The HMAC updates as you type.
- To check a signature, paste it into Compare with an expected HMAC; a label such as
sha256=is fine. - Copy the result, or open Code to compute the same HMAC in your own application.
Examples
Key: Jefe Message: what do ya want for nothing?
Hex: 5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843 Base64: W9zBRr9gdU5qBCQmCJV1x1oAPwidJzmDnexYuWTsOEM=
The official test vector; Try the RFC 4231 example loads it.
Expected: sha256=5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843
Match — HMAC-SHA-256 (hex)
The label is ignored for the comparison; the bytes are compared in constant time.
Key: 131 bytes of 0xaa (hex) Message: Test Using Larger Than Block-Size Key - Hash Key First
60e431591ee0b67f0d8a26aacbf5b77f8e0bc6213728c5140546040f0ee37f54
RFC 4231 test case 6: keys longer than 64 bytes are hashed first, which the key note explains.
Common uses
- Verifying webhook deliveries from payment, Git hosting and messaging services while you build the receiving endpoint.
- Signing API requests and debugging "signature does not match" errors.
- Creating or checking HS256/HS384/HS512 JWT signatures by hand.
- Producing test vectors for your own HMAC implementation, in any of four output formats.
How HMAC works
HMAC(K, m) = H((K′ ⊕ opad) ∥ H((K′ ⊕ ipad) ∥ m)). K′ is the key padded with zeros to the hash's block size (64 bytes for SHA-1 and SHA-256, 128 for SHA-384 and SHA-512) — or first hashed if it is longer — and ipad and opad are the bytes 0x36 and 0x5c repeated. The two nested hashes are why an HMAC cannot be extended or forged without the key, unlike a plain hash of key + message.
Collision attacks on MD5 and SHA-1 do not directly break HMAC, which is why HMAC-SHA-1 still appears in one-time-password apps and older webhook formats. Even so, MD5 is long obsolete and NIST has asked everyone to stop using SHA-1 by 31 December 2030 (NIST): use HMAC-SHA-256 or stronger for anything new.
Choosing a key
RFC 2104 §3: the key "can be of any length", but "less than L bytes is strongly discouraged" — L being the hash output, 32 bytes for HMAC-SHA-256 — and keys "need to be chosen at random" and periodically refreshed. A memorable word is not a good key. Create one with the API Key & Secret Generator (32 random bytes, in hex or Base64) and enter it here with the matching Key format: the same characters entered as Text and as Hex are different keys.
Verifying signatures safely
- Compute the HMAC over the exact bytes that were signed: the raw request body, not JSON you parsed and re-serialised, with the original whitespace and line endings. Some services sign more than the body (for example a timestamp joined to it) — check their documentation.
- Compare with a constant-time function, never
==, so an attacker cannot learn the right signature byte by byte from response times:crypto.timingSafeEqual(Node.js),hmac.compare_digest(Python),hash_equals(PHP),hmac.Equal(Go),MessageDigest.isEqual(Java),OpenSSL.secure_compare(Ruby) orCryptographicOperations.FixedTimeEquals(.NET). - Reject old messages: include a timestamp or nonce in what is signed so a captured request cannot be replayed.
Limitations
- Text is hashed exactly as it appears in the box, as UTF-8. Browsers turn pasted Windows line endings (CRLF) into LF, so choose Line breaks: CRLF when the original used them, or hash the original file with File.
- Files up to 128 MB are hashed with the browser's fast built-in engine for SHA-1 and SHA-2; larger files, and SHA-224, SHA-3 and MD5, are computed in JavaScript, which takes longer on big files and slow phones.
- The key and message are never saved: they are gone when you close or reload the page.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Is my secret key sent anywhere?
No. The HMAC is calculated by your browser; the key, message and files never leave your device, and the page works offline once loaded.
Why doesn't my HMAC match the one I expected?
Usually the bytes differ: extra or missing whitespace or a trailing newline, LF instead of CRLF line endings, JSON that was re-formatted, or text in another encoding. Next check the key format (a hex key typed as Text is a different key), the algorithm and the output encoding (hex vs Base64). Compare tries every algorithm and encoding it computed and tells you if one of them matches.
What is the difference between an HMAC and a hash?
Anyone can compute a hash such as SHA-256 of a message, so it only detects accidental changes. An HMAC also needs the secret key, so it detects deliberate tampering as well. Use the Hash Generator for checksums.
Is an HMAC a digital signature?
Not quite: both sides share the same key, so anyone who can verify an HMAC can also create one. Digital signatures (RSA, ECDSA, Ed25519) use a private key to sign and a public key to verify, so they also prove who signed.
Is HMAC-SHA-1 still safe?
As an HMAC it has no known practical attack, and it is still used by TOTP codes and older webhook formats. NIST nevertheless asks for SHA-1 to be phased out by the end of 2030, so choose HMAC-SHA-256 or stronger when you can.