Developer / Signatures

HMAC Generator (SHA-256, SHA-512)

Generate an HMAC signature for a message and secret key with SHA-256, SHA-384, SHA-512, or SHA-1, in hex and Base64, to test webhook and API signatures.

HMAC Generator (SHA-256, SHA-512): HMAC combines a secret key with a message through a hash function, so only someone with the key can produce the same signature. It is computed with your browser's Web Crypto API, the same implementation the browser uses for HTTPS. An empty key is allowed; it is treated as a key of zero bytes, as the HMAC standard defines. Runs 100% locally in your browser with zero server file uploads.

Runs
In your browser
Cost
Free · no sign-up
Availability
Ready to use
HMAC generatorLocal processing

Runs entirely in your browser

Hex—
Base64—

The message is read as UTF-8 text, exactly as typed, including spaces and line breaks; a trailing newline changes the result. Webhooks from services such as Stripe and GitHub are signed with HMAC-SHA256 this way.

Verifying a webhook

Take the raw request body before any parsing, compute the HMAC with the shared secret, and compare it with the signature header using a constant-time comparison, so timing does not leak how many characters matched. Reject requests whose timestamp is more than a few minutes old to stop replays.

For a hash without a key, use the hash generator; for signed tokens, the JWT decoder.

Keys

A key as long as the hash output, 32 random bytes for SHA-256, gives the full strength; longer keys are hashed down first. Keep keys out of code repositories and rotate them if they leak.

How to use it

  1. Paste the message, exactly as sent, such as a webhook's raw body.
  2. Enter the secret key, as text or hexadecimal, and choose the hash.
  3. Compare the hex or Base64 result with the signature you received.

Privacy & limitations

The message and key stay in your browser; nothing is sent anywhere.

Related tools

Frequently asked questions

Why does my signature not match the webhook's?

The signed message must be the raw body byte for byte: parsing and re-serialising JSON, or a missing or extra newline, changes it. Some services sign a timestamp and the body together, such as Stripe's t=…,payload.

Is HMAC-SHA1 still safe?

For HMAC it is still considered secure, unlike SHA-1 for plain hashing, but new systems should use HMAC-SHA256.

Hex or Base64?

They are two ways of writing the same bytes; use whichever the service shows. GitHub uses hex with a sha256= prefix, many others Base64.

Free tool · runs in your browser · no account required