Skip to content
Sealpaste

HMAC Generator

Sign a message with a secret key using HMAC-SHA256 and friends, to debug webhook signatures and signed API requests.

Input type
Output

Text

HMACs

Enter the secret key to compute HMACs.

How to use it

  1. 1Paste the exact message (for webhooks: the raw request body, byte for byte).
  2. 2Enter the secret key.
  3. 3Compare the HMAC in hex or Base64 with the signature header you received.

Private by design

Everything runs in this browser tab. Your input is never uploaded, logged or saved on a server, and there are no public "recent" pages. Close the tab and it's gone.

How we keep it private

Examples

HMAC-SHA256

Input

Message: The quick brown fox jumps over the lazy dog
Key: key

Output

f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8

Why webhook signatures don’t match

When your computed HMAC differs from the provider’s, it is almost always one of these:

  • The body was parsed and re-serialized. Sign the raw bytes exactly as received.
  • Wrong encoding: some providers send hex, others Base64, sometimes with a prefix like "sha256=".
  • The signed string includes more than the body, e.g. a timestamp: "t=…" + "." + body.
  • A test secret is used against live events, or the reverse.

Frequently asked questions

Is my text or file sent anywhere?

No. Hashes are computed in your browser with the Web Crypto API (MD5 with a small local library). Hashing passwords or keys on a website that sends them to its server would defeat the point.

Is the key stored?

No. The key stays in this tab and is used only by your browser’s Web Crypto API.