HMAC Generator
Sign a message with a secret key using HMAC-SHA256 and friends, to debug webhook signatures and signed API requests.
Text
HMACs
Enter the secret key to compute HMACs.
How to use it
- 1Paste the exact message (for webhooks: the raw request body, byte for byte).
- 2Enter the secret key.
- 3Compare the HMAC in hex or Base64 with the signature header you received.
Private by design
Everything runs in this browser tab. Your input is never uploaded, logged or saved on a server, and there are no public "recent" pages. Close the tab and it's gone.
How we keep it privateExamples
Input
Message: The quick brown fox jumps over the lazy dog Key: key
Output
f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8
Why webhook signatures don’t match
When your computed HMAC differs from the provider’s, it is almost always one of these:
- The body was parsed and re-serialized. Sign the raw bytes exactly as received.
- Wrong encoding: some providers send hex, others Base64, sometimes with a prefix like "sha256=".
- The signed string includes more than the body, e.g. a timestamp: "t=…" + "." + body.
- A test secret is used against live events, or the reverse.
Frequently asked questions
Is my text or file sent anywhere?
No. Hashes are computed in your browser with the Web Crypto API (MD5 with a small local library). Hashing passwords or keys on a website that sends them to its server would defeat the point.
Is the key stored?
No. The key stays in this tab and is used only by your browser’s Web Crypto API.