HMAC Generator
Generate an HMAC signature from a message and a secret key, using SHA-256 by default.
Your result will appear here as soon as you add some input.
How to use it
- 1Paste your input into the input box, or type it directly.
- 2Adjust the options if you need something other than the defaults.
- 3The result updates as you type.
- 4Copy the result to your clipboard or download it as a file.
About the HMAC Generator
HMAC combines a message with a secret key so that anyone holding the key can verify the message has not been altered. It is the mechanism behind webhook signatures, API request signing and JWT’s HS256.
Unlike a plain hash of key plus message, HMAC is not vulnerable to length-extension. That is the whole reason the construction exists.
The key is used only inside this page and is never transmitted. Even so, treat any production secret pasted into any web page as one you should rotate.
Questions people ask
Is my secret key sent anywhere?
No. The signature is computed in your browser with the Web Crypto API, and neither the key nor the message leaves the page. As a matter of habit, still prefer a local script for production secrets.
Is your code uploaded to a server?
No. This tool runs entirely in your browser using standard web APIs, so your code never leaves your device. You can confirm it by opening your browser's network panel while the tool runs, or by disconnecting from the internet after the page has loaded.
Is it free, and do I need an account?
Yes, it is free, and there is no account, no sign-up and no watermark on the result. The project is funded by optional donations.