AI Tools Free

HMAC Generator

Calculate HMAC-SHA-256, SHA-384, or SHA-512 locally and copy hexadecimal or Base64 output.

Free to useNo sign-upRuns in your browser
Enter your details

Enter the inputs, then select Generate HMAC.

Your result
Enter your details

Result will appear here

How HMAC Generator works

Browser Web Crypto computes an HMAC from the UTF-8 message and key with the selected SHA algorithm, then represents the bytes as hexadecimal or Base64.

A nonempty key is required, while an empty message is allowed. This produces an authentication code; it does not encrypt the message or verify a remote request.

Web Crypto needs a secure context such as HTTPS or trusted localhost.

Reference: MDN: HMAC signing.

A text message and key connected to an HMAC output.
Illustration of the HMAC Generator workflow.

How to use HMAC Generator

Use the exact message and a UTF-8 text key, then choose the required hash and output encoding.

Match the signing inputs

Enter the literal UTF-8 key and exact message, preserving meaningful spaces and line breaks. Select SHA-256, SHA-384, or SHA-512 and the hexadecimal or Base64 output expected by the consumer.

Secret key (UTF-8)
HMAC Generator native input panel with the actual Secret key (UTF-8), Message, Hash algorithm settings used for this example.
Configure Secret key (UTF-8), Message, Hash algorithm; select Generate HMAC.

Compute the authentication code

Run the generator and inspect the HMAC output. The result identifies the selected algorithm, byte length, and output encoding; these must match the comparison you intend to make.

HMAC ready
HMAC Generator actual result panel showing HMAC ready.
Submitted result: HMAC ready. Bytes: 64.

Copy the selected encoding

Copy the generated code and keep its algorithm and encoding with it. Review the UTF-8 processing note when a comparison differs. A key that looks like hex is still text, and no remote verification occurs.

Output and export
HMAC Generator actual output and export region and result note after submitting the pictured settings.
Review the actual HMAC Generator output and visible Copy result controls. Read the result note.

When to use HMAC Generator

Compare a generated authentication code with a documented integration requirement.

Generate an HMAC for a webhook example

Reproduce the message text from an integration example and generate its HMAC using the stated algorithm. If the code differs, compare the exact key representation and message first. A visually similar request body can contain a different newline or different spacing.

Developer input and configuration represented by document cards.
Prepare the input. Concept illustration.

Compare hexadecimal and Base64 HMAC output

Generate hexadecimal and Base64 versions for the same message and algorithm when documenting an interface. They are representations of the authentication code, not separate encryption choices. Keep the encoding label with the copied value so another person can compare like with like.

A developer example flowing from input to reviewed output.
Inspect an example. Concept illustration.

Investigate a signing mismatch

Use a small known message to isolate the key, algorithm, and encoding before working with a longer payload. A matching small example narrows the investigation, but it does not prove that the full request signing process handles headers or canonicalization correctly.

Developer output handed to the next stage of a workflow.
Use the result in your workflow. Concept illustration.

Separate authentication from encryption

Compare authentication codes only when the message bytes, key bytes, algorithm, and output representation agree.

An HMAC is an authentication code computed from a message and a secret key. It does not hide the message or allow the original text to be recovered from the output.

The implementation uses browser Web Crypto with UTF-8 text. The application performs this computation locally; its result does not show that a remote service accepts the code or that a key is appropriate for that service.

A developer result reviewed alongside its source.
Review the returned output. Concept illustration.

Check the environment and key format

Confirm the exact text and selected options before comparing this code with another implementation.

Web Crypto needs a secure context such as HTTPS or trusted localhost. If generation fails before a result appears, check that context and the nonempty key before changing the message.

The text key is limited to 10000 characters and the message to 100000. When comparing external outputs, check raw key bytes, message bytes, algorithm, and encoding rather than assuming every HMAC interface uses text keys.

Input format and assumptions reviewed for a developer task.
Check format and assumptions. Concept illustration.

Calculate an HMAC for your message

Use the exact message and a UTF-8 text key, then choose the required hash and output encoding.

Generate an HMAC

HMAC Generator: common questions

Answers about using HMAC Generator and understanding its results.

Is the key interpreted as hex?

No. The entered key is UTF-8 text, even when it contains hexadecimal-looking characters.

Can I hash an empty message?

Yes, with a nonempty key.

Which hash algorithms can I select?

The form offers SHA-256, SHA-384, and SHA-512 HMAC, with hexadecimal or Base64 output.

Why does a final newline matter?

It changes the message bytes used in the computation. Preserve meaningful whitespace when comparing an expected HMAC.