HMAC Generator
Sign a message with a secret key, in your browser.
- 100% Free
- No Sign Up
- Works in Your Browser
HMAC generator
Sign a message with an HMAC key
More Developer Tools
View all tools- UUID generatorGenerate random v4 or time-ordered v7 UUIDs
- Password generatorCreate strong random passwords
- Random string generatorRandom strings, tokens and IDs
- Hash generatorMD5, SHA-1, SHA-256 and SHA-512 hashes
- Lorem ipsum generatorPlaceholder text for layouts
- JSON formatterPretty-print and indent JSON
- Base64 encode/decodeEncode and decode Base64 text
- JWT decoderDecode a JSON Web Token
- Timestamp converterConvert Unix epoch time to dates
Every everyday developer tool, right in your browser.
No installs. No uploads. No signup.
Browse all 36 tools- Developer tools
- 36
- Cheat sheets
- 10
- Bytes uploaded
- 0
How to use the HMAC generator
Three steps, all in your browser.
- 1
Choose what you need
Pick the type and how many. Results appear straight away.
- 2
Set the options
Choose the length, count or algorithm. The output updates instantly.
- 3
Copy the result
Copy the output in one click. Nothing is saved or sent anywhere.
HMAC Generator: what to know
The HMAC generator signs a message with a secret key using HMAC (RFC 2104) and SHA-256, SHA-384, SHA-512 or SHA-1, through the browser's Web Crypto API. The result is shown in hexadecimal or Base64, the two formats services use for signatures. Your key and message stay on your device.
An HMAC proves two things: that the message hasn't changed and that it was produced by someone who knows the key. Payment providers, Git hosting services and messaging platforms sign webhooks this way, sending the signature in a header. Your server recomputes the HMAC of the raw request body with the shared secret and compares the two, ideally with a constant-time comparison.
Signatures only match when every byte matches. The most common reasons a webhook check fails are hashing parsed and re-serialized JSON instead of the raw body, a different character encoding, a missing timestamp prefix that the provider includes in the signed string, or comparing hex with Base64.
Popular uses
- Debugging webhook signature verification
- Signing API requests that require an HMAC header
- Creating test signatures for unit tests
- Learning how message authentication works
Tips for the best result
- Read the provider's docs for the exact signed string: many sign 'timestamp.body', not the body alone.
- Use a test secret here, not your production key.
- HMAC-SHA1 is still secure as an HMAC, but choose SHA-256 for anything new.
Read how JustYourDev works and our privacy details. Code, data and files you use here are processed in your browser and are never sent to our server.