HMAC Generator
Create keyed HMAC-SHA signatures from a message and secret key locally.
Keyed HMAC signatures
An HMAC proves a message was created by someone holding a shared secret, which is how webhooks and API requests are verified. This generator computes HMAC-SHA signatures from a message and key using the browser’s Web Crypto, so you can reproduce or check a signature.
Because it uses SubtleCrypto, the signing is real and standards-based. It is handy for debugging webhook verification and understanding how a provider signs requests — though for genuine production secrets, be mindful of where you paste them.
Signatures, kept private
An HMAC combines your message with a shared secret, which is how a webhook receiver confirms a request is genuine. Both are processed in your browser, so the secret never leaves your device.
Frequently asked questions
What is an HMAC?
A signature made from a message and a secret key. Anyone with the same key can recompute it to check the message was not changed.
Is my secret key sent anywhere?
No. The signature is calculated with your browser's Web Crypto API, and the key stays on your device.
Why doesn't my HMAC match my server's?
Check the hash algorithm, that the key is the exact same bytes, and that the message matches exactly, including whitespace and line endings.
Related tools
Practical utilities for everyday web development work.