Search tools

Search for a command to run...

HMAC Generator

Create HMAC signatures with SHA-256, SHA-512, SHA-1 or MD5 from a message and secret key, as hex or Base64 — for webhooks and API signing.

How to use

  1. 1Enter the secret key and choose the algorithm.
  2. 2Paste the message (e.g. the raw webhook body) and compare the signature.

How it's calculated

HMAC(K, m) = H((K ⊕ opad) ‖ H((K ⊕ ipad) ‖ m)) as defined in RFC 2104.

Frequently asked questions

What is HMAC used for?

Proving a message came from someone with the shared secret and wasn't changed — e.g. Stripe, GitHub and Shopify webhook signatures.

Why doesn't my webhook signature match?

Sign the exact raw request body, byte for byte. Re-serialized JSON, changed whitespace or a different encoding breaks the match.

Is my secret key sent anywhere?

No. The HMAC is computed in your browser; neither the key nor the message leaves your device.