HMAC Generator and Verifier
Generate or verify keyed message authentication codes using SHA-256, SHA-384, or SHA-512.
Message
HMAC settings
Generated HMAC
Enter a message and secret
The generated or verified HMAC result will appear here automatically.
Message authentication
Verify message integrity using a shared secret
HMAC combines a cryptographic hash function with a secret key to verify both the integrity and authenticity of data.
Common use cases
HMAC is widely used for webhook signatures, API request authentication, signed URLs, JWT HS256/HS384/HS512 signatures, and tamper detection.
Keep the secret secure
Anyone with the shared secret can generate valid HMAC signatures. Store secrets securely, rotate them regularly, and never expose them in client-side applications.
Guide
About HMAC Generator and Verifier
HMAC combines a cryptographic hash with a shared secret to authenticate message integrity and origin.
This tool generates and verifies HMAC values using SHA-256, SHA-384, or SHA-512.
Anyone who obtains the shared secret can create valid HMACs, so key protection is essential.
Common HMAC uses
HMAC is used when two systems share a secret and need to detect message modification.
- Webhook signatures
- API request signing
- JWT HS256, HS384, and HS512
- Signed URLs
- Message-integrity checks
HMAC versus plain hashing
A plain hash proves only that two inputs match. HMAC also requires knowledge of a secret key.
Verification safety
Production implementations should compare authentication codes in constant time to reduce timing side channels.
Secret management
Use strong random secrets, store them securely, rotate exposed values, and separate secrets across environments and integrations.
FAQ
Frequently asked questions
What is HMAC?
HMAC is a keyed message authentication code built from a cryptographic hash and shared secret.
Is HMAC encryption?
No. HMAC provides integrity and authenticity, not confidentiality.
Which HMAC algorithm should I use?
HMAC-SHA-256 is a common default; SHA-384 and SHA-512 are also supported.
Why does verification fail?
The secret, message bytes, algorithm, or output encoding may not match the original signer.
Can I use HMAC for webhook verification?
Yes, if you reproduce the provider's exact signing procedure and compare safely.
Is my secret uploaded?
Generation and verification are intended to run locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
Hash Generator
Generate SHA-256, SHA-384, and SHA-512 hashes locally.
Cryptography
JWT Signature Verifier
Verify HMAC JWT signatures and important claims locally.
Authentication
AES Encrypt / Decrypt
Encrypt and decrypt text with password-based AES-256-GCM.
Cryptography
Base64 Encode / Decode
Encode and decode Base64 data directly in your browser.
Encoding & Data
SRI Hash Generator
Generate and verify integrity hashes for scripts and stylesheets.
Cryptography
Website Security Scanner
Inspect HTTPS, TLS, headers, cookies, and common security configuration issues.
Website Security