HMAC Generator – SHA-1, SHA-256, SHA-512

Sign a message with a secret key using HMAC and get all four SHA variants at once — useful for testing webhook and API signatures.

Loading tool…

About the HMAC Generator

HMAC (RFC 2104) combines a secret key with a hash function to produce a message authentication code: only someone with the key can compute it, and any change to the message changes the result. It is how GitHub, Stripe, Slack and Shopify sign webhooks and how many APIs (including AWS Signature V4) authenticate requests. The known test vector: key key and message The quick brown fox jumps over the lazy dog give HMAC-SHA256 f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8.

Keys can be entered as UTF-8 text, hex or Base64, because providers distribute secrets in different forms — check whether a Base64-looking secret is meant to be used as text or decoded to bytes first. The message is hashed as UTF-8 exactly as typed, so watch for trailing newlines and re-serialised JSON: webhook signatures are computed over the raw request body.

The calculation uses crypto.subtle.sign('HMAC', …) in your browser; neither key nor message is transmitted. When verifying signatures in your own code, compare them with a constant-time function such as crypto.timingSafeEqual to avoid timing attacks.

How to use it

  1. Paste the message (for webhooks, the raw request body).
  2. Enter the secret key and choose whether it is text, hex or Base64.
  3. Choose hex or Base64 output.
  4. Copy the HMAC for the algorithm you need.

Frequently asked questions

Why does my webhook signature not match?
Most often the body was parsed and re-serialised, changing whitespace or key order. Sign the exact raw bytes received. Also check the key encoding and any prefix such as sha256=.
Is HMAC the same as hashing key + message?
No. sha256(key + message) is vulnerable to length-extension attacks. HMAC's nested construction is not.
How long should an HMAC key be?
At least as long as the hash output (32 bytes for SHA-256), generated randomly. Longer keys than the block size are hashed first.
Is HMAC-SHA1 still safe?
HMAC-SHA1 is not affected by SHA-1 collision attacks and remains secure in practice, but prefer HMAC-SHA256 for new systems.

Related tools