Overview
Enter a secret key and a message to compute a genuine HMAC (Hash-based Message Authentication Code) using the browser's native Web Crypto API - not a simplified "hash(secret + message)" approximation, which is an insecure anti-pattern that behaves very differently from a real HMAC. Under the hood this imports your key with `crypto.subtle.importKey` using the HMAC algorithm and the hash function you pick (SHA-256, SHA-384, or SHA-512, plus SHA-1 clearly marked as legacy for interoperating with older systems), then signs the message with `crypto.subtle.sign`, exactly the construction a real backend or API client would use. Output is available in hex or Base64. HMAC is fundamentally different from plain hashing: it requires a shared secret, which is what lets a recipient prove a message came from someone holding that secret and wasn't altered in transit - it is an integrity and authentication mechanism, not encryption, and it does not hide or protect the message contents themselves. Useful for verifying a webhook signature by hand, testing an API integration that signs requests, or checking that your own HMAC implementation matches the standard. Runs entirely client-side, asynchronously via Web Crypto - your secret and message are never sent anywhere.
Best for: Verifying a webhook signature by hand or testing that a custom API integration signs requests correctly
How to use this tool
- Enter your secret key and message. Both are UTF-8 encoded before signing, matching how most HMAC implementations treat string input.
- Pick a hash algorithm. SHA-256, SHA-384, or SHA-512 for modern use, or SHA-1 when you need to match a legacy system.
- Choose hex or Base64 output. Match whichever format the system you're comparing against expects.
- Compare against your real signature. Match the computed value against a webhook header or API signature to confirm your implementation is correct.
Why use this tool
Real Web Crypto HMAC, not a workaround
Uses crypto.subtle.importKey and crypto.subtle.sign with the HMAC algorithm directly - never a hash(secret+message) substitute.
Never sent anywhere
The secret and message are processed entirely in your browser and never transmitted, matching the sensitivity of a real signing key.
Multiple algorithms and encodings
SHA-256/384/512 for modern use, legacy SHA-1 clearly marked, and both hex and Base64 output.
Clear about what HMAC is (and isn't)
Explicitly explained as integrity/authentication, not encryption - the message itself is never hidden.
Frequently asked questions
hash-generator computes a plain, unkeyed hash (MD5/SHA-1/256/512) of text alone. HMAC additionally requires a secret key and uses a specific, standardized construction (not just concatenating the secret and message before hashing, which is insecure) so that only someone holding the same key can produce or verify the same signature - it proves both integrity and authenticity, not just that the data matches a known value.
No. HMAC proves a message wasn't tampered with and came from someone holding the secret key, but it doesn't hide the message contents at all - the message itself is sent in the clear. Use actual encryption (like AES) if you need confidentiality; use HMAC alongside it (or on its own) when you need to detect tampering or authenticate the sender.
The computation happens entirely in your browser via the Web Crypto API - the secret and message are never sent to any server. That said, treat any real production secret with the same caution you would anywhere: prefer a disposable test key when just verifying behavior.