About the HMAC Generator
HMAC (RFC 2104) combines a secret key with a hash function to produce a message authentication code: only someone with the key can compute it, and any change to the message changes the result. It is how GitHub, Stripe, Slack and Shopify sign webhooks and how many APIs (including AWS Signature V4) authenticate requests. The known test vector: key key and message The quick brown fox jumps over the lazy dog give HMAC-SHA256 f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8.
Keys can be entered as UTF-8 text, hex or Base64, because providers distribute secrets in different forms — check whether a Base64-looking secret is meant to be used as text or decoded to bytes first. The message is hashed as UTF-8 exactly as typed, so watch for trailing newlines and re-serialised JSON: webhook signatures are computed over the raw request body.
The calculation uses crypto.subtle.sign('HMAC', …) in your browser; neither key nor message is transmitted. When verifying signatures in your own code, compare them with a constant-time function such as crypto.timingSafeEqual to avoid timing attacks.
How to use it
- Paste the message (for webhooks, the raw request body).
- Enter the secret key and choose whether it is text, hex or Base64.
- Choose hex or Base64 output.
- Copy the HMAC for the algorithm you need.