Developer

JSON (22)API (9)Text (31)Security (11)Network (1)

SEO & Content

SEO (11)AI (7)Design (8)Image (9)

Data & Math

XML (6)Math (6)Database (3)Date (4)

More Tools

Next.js (5)PDF (5)Video (3)Random (2)
WorkspacesAll ToolsAboutPrivacyTermsContact

© 2026 Web Util Slyce. All tools run client-side — your data stays private.

SecurityHMAC Generator

HMAC Generator

HMAC generator. Generate HMAC-SHA256, SHA-384, and SHA-512 hashes simultaneously with custom secret key input. Uses Web Crypto API.

100% browser-based — your data never leaves your device

Multiple AlgorithmsSecret KeyReal-TimeLocal Processing
HomeSecurityHMAC Generator
All tools
Tool

Generate HMAC hashes with SHA-256, SHA-384, and SHA-512 algorithms.

Multiple Algorithms

HMAC-SHA256, HMAC-SHA384, and HMAC-SHA512 all generated simultaneously.

Secret Key

Custom secret key input for generating unique HMAC signatures.

Real-Time

HMAC hashes update as you type or change the secret key.

Local Processing

All hashing done locally using Web Crypto API — nothing is uploaded.

How to Use

1

Enter your message

Type or paste the message you want to sign with HMAC.

2

Set your secret key

Enter a secret key that only you and the receiver know.

3

Choose an algorithm

Select HMAC-SHA256, HMAC-SHA384, or HMAC-SHA512.

4

Copy the HMAC hash

Click any generated hash to copy it for use in your application.

0 chars0 words0 lines
Ln 1, Col 1

Ctrl+Enter to generate hmac

Frequently Asked Questions

HMAC (Hash-based Message Authentication Code) is used to verify both the integrity and authenticity of a message using a shared secret key.

Related Tools

JWT Decoder

Decode and inspect JWT tokens instantly.

Password Generator

Generate strong, secure random passwords with customizable options.

Passphrase Generator

Generate memorable, secure passphrases from word lists.

UUID Generator

Generate UUID v4 identifiers instantly.

UUID Validator

Validate UUID strings and identify the version (v1, v2, v3, v4, v5).

Hash Generator

Generate SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text.

JWT Generator

Generate signed JWT tokens for testing with custom headers and payloads.

Bcrypt Hash Generator

Generate bcrypt password hashes with configurable salt rounds.

API Key Generator

Generate cryptographically secure API keys in hex, base64, alphanumeric, and UUID formats.

HMAC Generator

Generate HMAC hashes with SHA-256, SHA-384, and SHA-512 algorithms.

AES Encrypt

Encrypt and decrypt text using AES-256-GCM with a password-based key.

Back to Security Tools
Related:JWT DecoderPassword GeneratorPassphrase GeneratorUUID Generator

How to Use the Free Client-Side HMAC Generator

HMAC takes a message and a shared secret key and produces a signature that proves both integrity and authenticity. This generator computes three variants at once using the Web Crypto API, entirely within your browser.

  1. Enter the message you want to sign.
  2. Provide a secret key known only to you and the intended receiver.
  3. Select HMAC-SHA256, HMAC-SHA384, or HMAC-SHA512.
  4. Click any generated signature to copy it for use in your application.

When to Use HMAC Generator

HMAC is the workhorse of authenticated messaging. Webhook providers sign every delivery with a keyed hash so that you can verify the payload really came from them and was not tampered with in transit. This tool is ideal for computing or checking those signatures during integration, for signing inter-service messages in a microservice architecture, and for generating the keyed digests used inside OAuth flows and JWT signing contexts.

The simultaneous output of all three algorithms is a small convenience with real payoff. When you are diagnosing a signature mismatch, seeing SHA-256, SHA-384, and SHA-512 side by side lets you confirm your server is using the same variant as the caller, which is a surprisingly common source of 403s and invalid-signature errors.

HMAC Generator Tips and Best Practices

  1. Use a cryptographically random secret of at least 256 bits. HMAC's strength rests entirely on the secrecy and quality of the key, so an empty or guessable key turns the signature into theater.
  2. Understand what HMAC does and does not do. It proves authenticity and integrity, but the message itself stays readable, so never assume a signed payload is encrypted.
  3. Store secret keys in environment variables or a key manager. Hardcoding them in code or committing them to version control is how signing secrets leak.
  4. Stick with SHA-256 or SHA-512. The SHA-1 variants are deprecated for security-sensitive applications, so avoid them in anything headed to production.

Why Client-Side Privacy Matters for signing messages and verifying their authenticity

The whole point of HMAC is that only parties sharing a secret can produce a valid signature. If you paste that secret into a server-based generator to compute a signature, the secret is compromised the moment it leaves your browser, and the authenticity guarantee evaporates.

This generator performs every hash locally. Your message and secret key never leave your device, no server sees either value, and the signature you copy out is produced by code running entirely in your own browser.

How to Use HMAC Generator

1

Enter your message

Type or paste the message you want to sign with HMAC.

2

Set your secret key

Enter a secret key that only you and the receiver know.

3

Choose an algorithm

Select HMAC-SHA256, HMAC-SHA384, or HMAC-SHA512.

4

Copy the HMAC hash

Click any generated hash to copy it for use in your application.

Examples

Practical examples to help you get the most out of HMAC Generator:

Generate HMAC-SHA256

// Message: Hello, World!
// Secret: my-secret-key
// HMAC-SHA256: 8f7d3c2e9b6a5d1f4c8e0a3b6d9f2c7e5a1b4d8c0f3e6a9b2c5d7f8e0a3b6c

Common Mistakes and How to Avoid Them

Using an empty or weak secret key

HMAC security depends entirely on the secrecy and strength of the key. Use a cryptographically random key of at least 32 bytes (256 bits).

Confusing HMAC with encryption

HMAC provides authentication and integrity, not confidentiality. The message is still visible — HMAC only proves it hasn't been tampered with.

Frequently Asked Questions

What is HMAC used for?

HMAC (Hash-based Message Authentication Code) is used to verify both the integrity and authenticity of a message using a shared secret key.

What algorithms are supported?

HMAC-SHA256, HMAC-SHA384, and HMAC-SHA512 are all supported. Results for all three algorithms are shown simultaneously.

How is HMAC different from regular hashing?

HMAC combines the data with a secret key before hashing. Regular hashing (like SHA-256) produces the same hash for the same data, while HMAC requires the key to verify.

Is my data sent to a server?

No. All hashing is done locally using the Web Crypto API. Your data and secret key never leave your browser.

Key Features

Multiple Algorithms

HMAC-SHA256, HMAC-SHA384, and HMAC-SHA512 all generated simultaneously.

Secret Key

Custom secret key input for generating unique HMAC signatures.

Real-Time

HMAC hashes update as you type or change the secret key.

Local Processing

All hashing done locally using Web Crypto API — nothing is uploaded.

Common Use Cases

HMAC Generator is useful in a variety of scenarios across different workflows:

Verifying API request authenticity using HMAC signatures in webhook integrations

Generating message authentication codes for secure inter-service communication

Creating signed payloads for OAuth and JWT token signing contexts

Tips & Best Practices

Never hardcode keys in code

Store HMAC secret keys in environment variables or secure key management systems. Never commit keys to version control.

SHA-256 is the recommended minimum

SHA-1 is deprecated for security-sensitive applications. Use HMAC-SHA256 or HMAC-SHA512 for production systems.

More Tools in This Workspace

Explore more tools in the Security workspace:

JWT Decoder

Decode and inspect JWT tokens instantly.

Password Generator

Generate strong, secure random passwords with customizable options.

Passphrase Generator

Generate memorable, secure passphrases from word lists.

UUID Generator

Generate UUID v4 identifiers instantly.

UUID Validator

Validate UUID strings and identify the version (v1, v2, v3, v4, v5).

Hash Generator

Generate SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text.