Free · Private · In-Browser

HMAC Generator

Create keyed HMAC-SHA signatures from a message and secret key locally.

Output
 

Keyed HMAC signatures

An HMAC proves a message was created by someone holding a shared secret, which is how webhooks and API requests are verified. This generator computes HMAC-SHA signatures from a message and key using the browser’s Web Crypto, so you can reproduce or check a signature.

Because it uses SubtleCrypto, the signing is real and standards-based. It is handy for debugging webhook verification and understanding how a provider signs requests — though for genuine production secrets, be mindful of where you paste them.

Signatures, kept private

An HMAC combines your message with a shared secret, which is how a webhook receiver confirms a request is genuine. Both are processed in your browser, so the secret never leaves your device.

Frequently asked questions

What is an HMAC?

A signature made from a message and a secret key. Anyone with the same key can recompute it to check the message was not changed.

Is my secret key sent anywhere?

No. The signature is calculated with your browser's Web Crypto API, and the key stays on your device.

Why doesn't my HMAC match my server's?

Check the hash algorithm, that the key is the exact same bytes, and that the message matches exactly, including whitespace and line endings.

Take it further
Developer Tools

Practical utilities for everyday web development work.

Learn more