Enter a message and a secret key below to generate an HMAC. Everything runs in your browser using the Web Crypto API — your message and key are never sent to our server.
Computed locally in your browser using the Web Crypto API — your message and secret key are never sent to our server.
Computed entirely in your browser — nothing you enter here is sent to our server.
Computing…
About HMAC
An HMAC (Hash-based Message Authentication Code) combines a message with a secret key to produce a value that proves both the message’s integrity and that whoever produced it knew the key — used widely in API authentication (e.g. signing webhook payloads), JWT signatures, and message verification. Choose the hash algorithm your target system expects (SHA-256 is the most common default). This tool uses your browser’s native Web Crypto API to compute it.
FAQ
Is my message or key uploaded anywhere?
No. The HMAC is computed entirely in your browser using the Web Crypto API. Neither your message nor your secret key is ever sent to our server.
How is HMAC different from a plain hash?
A plain hash (like SHA-256 alone) proves a message wasn’t altered, but anyone can compute it. An HMAC additionally requires the secret key, so it also proves the message came from someone who knew that key — that’s what makes it useful for authentication, not just integrity checking.
Which algorithm should I choose?
Whichever your target system expects — SHA-256 is the most common default for new systems (e.g. HMAC-SHA256 is standard for many webhook signature schemes and JWTs).