HMAC Generator
Create HMAC signatures with SHA-256, SHA-512, SHA-1 or MD5 from a message and secret key, as hex or Base64 — for webhooks and API signing.
How to use
- 1Enter the secret key and choose the algorithm.
- 2Paste the message (e.g. the raw webhook body) and compare the signature.
How it's calculated
HMAC(K, m) = H((K ⊕ opad) ‖ H((K ⊕ ipad) ‖ m)) as defined in RFC 2104.
Frequently asked questions
What is HMAC used for?
Proving a message came from someone with the shared secret and wasn't changed — e.g. Stripe, GitHub and Shopify webhook signatures.
Why doesn't my webhook signature match?
Sign the exact raw request body, byte for byte. Re-serialized JSON, changed whitespace or a different encoding breaks the match.
Is my secret key sent anywhere?
No. The HMAC is computed in your browser; neither the key nor the message leaves your device.