HMAC generator. Generate HMAC-SHA256, SHA-384, and SHA-512 hashes simultaneously with custom secret key input. Uses Web Crypto API.
100% browser-based — your data never leaves your device
Generate HMAC hashes with SHA-256, SHA-384, and SHA-512 algorithms.
Type or paste the message you want to sign with HMAC.
Enter a secret key that only you and the receiver know.
Select HMAC-SHA256, HMAC-SHA384, or HMAC-SHA512.
Click any generated hash to copy it for use in your application.
Ctrl+Enter to generate hmac
Decode and inspect JWT tokens instantly.
Password GeneratorGenerate strong, secure random passwords with customizable options.
Passphrase GeneratorGenerate memorable, secure passphrases from word lists.
UUID GeneratorGenerate UUID v4 identifiers instantly.
UUID ValidatorValidate UUID strings and identify the version (v1, v2, v3, v4, v5).
Hash GeneratorGenerate SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text.
JWT GeneratorGenerate signed JWT tokens for testing with custom headers and payloads.
Bcrypt Hash GeneratorGenerate bcrypt password hashes with configurable salt rounds.
API Key GeneratorGenerate cryptographically secure API keys in hex, base64, alphanumeric, and UUID formats.
HMAC GeneratorGenerate HMAC hashes with SHA-256, SHA-384, and SHA-512 algorithms.
AES EncryptEncrypt and decrypt text using AES-256-GCM with a password-based key.
HMAC takes a message and a shared secret key and produces a signature that proves both integrity and authenticity. This generator computes three variants at once using the Web Crypto API, entirely within your browser.
HMAC is the workhorse of authenticated messaging. Webhook providers sign every delivery with a keyed hash so that you can verify the payload really came from them and was not tampered with in transit. This tool is ideal for computing or checking those signatures during integration, for signing inter-service messages in a microservice architecture, and for generating the keyed digests used inside OAuth flows and JWT signing contexts.
The simultaneous output of all three algorithms is a small convenience with real payoff. When you are diagnosing a signature mismatch, seeing SHA-256, SHA-384, and SHA-512 side by side lets you confirm your server is using the same variant as the caller, which is a surprisingly common source of 403s and invalid-signature errors.
The whole point of HMAC is that only parties sharing a secret can produce a valid signature. If you paste that secret into a server-based generator to compute a signature, the secret is compromised the moment it leaves your browser, and the authenticity guarantee evaporates.
This generator performs every hash locally. Your message and secret key never leave your device, no server sees either value, and the signature you copy out is produced by code running entirely in your own browser.
Type or paste the message you want to sign with HMAC.
Enter a secret key that only you and the receiver know.
Select HMAC-SHA256, HMAC-SHA384, or HMAC-SHA512.
Click any generated hash to copy it for use in your application.
Practical examples to help you get the most out of HMAC Generator:
// Message: Hello, World! // Secret: my-secret-key // HMAC-SHA256: 8f7d3c2e9b6a5d1f4c8e0a3b6d9f2c7e5a1b4d8c0f3e6a9b2c5d7f8e0a3b6c
HMAC security depends entirely on the secrecy and strength of the key. Use a cryptographically random key of at least 32 bytes (256 bits).
HMAC provides authentication and integrity, not confidentiality. The message is still visible — HMAC only proves it hasn't been tampered with.
HMAC (Hash-based Message Authentication Code) is used to verify both the integrity and authenticity of a message using a shared secret key.
HMAC-SHA256, HMAC-SHA384, and HMAC-SHA512 are all supported. Results for all three algorithms are shown simultaneously.
HMAC combines the data with a secret key before hashing. Regular hashing (like SHA-256) produces the same hash for the same data, while HMAC requires the key to verify.
No. All hashing is done locally using the Web Crypto API. Your data and secret key never leave your browser.
HMAC-SHA256, HMAC-SHA384, and HMAC-SHA512 all generated simultaneously.
Custom secret key input for generating unique HMAC signatures.
HMAC hashes update as you type or change the secret key.
All hashing done locally using Web Crypto API — nothing is uploaded.
HMAC Generator is useful in a variety of scenarios across different workflows:
Verifying API request authenticity using HMAC signatures in webhook integrations
Generating message authentication codes for secure inter-service communication
Creating signed payloads for OAuth and JWT token signing contexts
Store HMAC secret keys in environment variables or secure key management systems. Never commit keys to version control.
SHA-1 is deprecated for security-sensitive applications. Use HMAC-SHA256 or HMAC-SHA512 for production systems.
Explore more tools in the Security workspace:
JWT Decoder
Decode and inspect JWT tokens instantly.
Password Generator
Generate strong, secure random passwords with customizable options.
Passphrase Generator
Generate memorable, secure passphrases from word lists.
UUID Generator
Generate UUID v4 identifiers instantly.
UUID Validator
Validate UUID strings and identify the version (v1, v2, v3, v4, v5).
Hash Generator
Generate SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text.