HMAC Generator
Compute HMAC-SHA1, HMAC-SHA256, HMAC-SHA384 and HMAC-SHA512 signatures of any message with a secret key, using the Web Crypto API. Keys never leave the browser.
Sign a message with HMAC-SHA256
Sign the classic test message with a shared secret and see the resulting SHA-256 HMAC in hex.
FAQ
What is an HMAC?
A Hash-based Message Authentication Code. It’s a keyed hash that proves both integrity (the message wasn’t changed) and authenticity (it was produced by someone holding the secret key).
HMAC vs a plain hash — what’s the difference?
A plain hash like SHA-256 has no secret, so anyone can compute it. An HMAC mixes in a secret key, so only parties who share the key can create or verify the signature.
Which algorithm should I use?
Use HMAC-SHA256 unless you have a specific compatibility requirement. SHA-1 HMACs are deprecated, and SHA-384/512 add no benefit for most use cases.
Why do I need a key?
The key is what makes the MAC secret. Anyone with the key can forge signatures, so treat it like a credential — use a long random value and never share it over plaintext channels.