HM

HMAC Generator

Compute HMAC-SHA1, HMAC-SHA256, HMAC-SHA384 and HMAC-SHA512 signatures of any message with a secret key, using the Web Crypto API. Keys never leave the browser.

Message
Output

Sign a message with HMAC-SHA256

Sign the classic test message with a shared secret and see the resulting SHA-256 HMAC in hex.

FAQ

What is an HMAC?

A Hash-based Message Authentication Code. It’s a keyed hash that proves both integrity (the message wasn’t changed) and authenticity (it was produced by someone holding the secret key).

HMAC vs a plain hash — what’s the difference?

A plain hash like SHA-256 has no secret, so anyone can compute it. An HMAC mixes in a secret key, so only parties who share the key can create or verify the signature.

Which algorithm should I use?

Use HMAC-SHA256 unless you have a specific compatibility requirement. SHA-1 HMACs are deprecated, and SHA-384/512 add no benefit for most use cases.

Why do I need a key?

The key is what makes the MAC secret. Anyone with the key can forge signatures, so treat it like a credential — use a long random value and never share it over plaintext channels.

Updated 2026-08-10 · Runs in your browser — your data never leaves this page unless the tool explicitly says it makes a network check.