HMAC Generator (SHA-256, SHA-1, SHA-512, MD5)
Free HMAC generator. Sign a message with a secret key using HMAC-SHA256, SHA-1, SHA-384, SHA-512 or MD5, and check a webhook signature — all in your browser.
Enter a secret and a message to see the HMAC.
HMAC is not the hash of your secret joined to your message. It runs the hash twice over two different paddings of the key, and that structure is what stops a length-extension attack: with a plain SHA256(secret + message) an attacker who never learns the secret can still append to your message and produce a valid digest for the longer one. That is the whole reason HMAC exists.
When you check a signature in your own code, compare it with a constant-time function — crypto.timingSafeEqual in Node, hmac.compare_digest in Python, hash_equals in PHP — not with ===. An ordinary comparison returns as soon as two bytes differ, and that timing difference is enough to recover a valid signature one byte at a time.
Everything here runs in your browser — SHA-1 through SHA-512 on the built-in Web Crypto API, MD5 in JavaScript because Web Crypto deliberately dropped it — and nothing is uploaded. Even so, a production signing key is worth rotating rather than pasting anywhere; use a throwaway value if you only need to check the shape of a signature.
Frequently asked questions
- What is the difference between HMAC and a plain hash?
- A hash takes one input; an HMAC takes a message and a secret key, so only someone holding the key can produce a valid tag. HMAC is also not simply the hash of the key joined to the message. It runs the hash twice, over two different paddings of the key, and that structure is what defeats a length-extension attack: against a naive SHA256(secret + message), an attacker who never learns the secret can still append data and compute a valid digest for the longer message. Against HMAC they cannot.
- My signature does not match the one my API sent. Why?
- Almost always because the secret is being read differently at the two ends. A key like 4a3f9c1e is eight characters of text but four bytes of hex, and those two readings produce completely unrelated MACs — so pick the tab that matches how your provider stores the key. The next most common causes are the algorithm (a 64-character hex signature is SHA-256; 40 is SHA-1) and the message bytes, where a trailing newline or CRLF line endings picked up in transit change the result. Paste the signature you were sent into the compare box and the tool tries every one of those combinations and names the one that reproduces it.
- Which key and output formats are supported?
- The secret can be plain text, hex or Base64, and the message the same, because APIs disagree about all of them. Every result is shown at once as lowercase hex, uppercase hex, Base64 and Base64url, so you can copy whichever form your provider expects. Case-different hex and Base64 versus Base64url are the same value, and the comparison treats them as such.
- Is HMAC-MD5 or HMAC-SHA1 still safe to use?
- For new work use HMAC-SHA256. MD5 and SHA-1 are both broken for collision resistance, which is what rules them out for digital signatures and certificates. HMAC is a different setting and no practical forgery against HMAC-MD5 or HMAC-SHA1 is known, which is why they still appear in older payment, telecom and AWS Signature V2 integrations — both are included here so you can reproduce those. That is a reason to keep verifying them, not to choose them.
- Should I compare signatures with == in my own code?
- No. Use a constant-time comparison: crypto.timingSafeEqual in Node, hmac.compare_digest in Python, hash_equals in PHP, subtle.ConstantTimeCompare in Go. An ordinary comparison stops at the first differing byte, and the timing difference leaks enough for an attacker to build a valid signature one byte at a time.
- Is my secret key sent anywhere?
- No. The HMAC is computed entirely in your browser and neither the key nor the message leaves your device. Even so, treat a live production signing key as worth rotating rather than pasting into any tool, including this one.