HMAC Generator and Verifier

Generate or verify keyed message authentication codes using SHA-256, SHA-384, or SHA-512.

Browser onlyGenerate & VerifyWeb Crypto

Message

HMAC settings

Generated HMAC

Enter a message and secret

The generated or verified HMAC result will appear here automatically.

Message authentication

Verify message integrity using a shared secret

HMAC combines a cryptographic hash function with a secret key to verify both the integrity and authenticity of data.

Common use cases

HMAC is widely used for webhook signatures, API request authentication, signed URLs, JWT HS256/HS384/HS512 signatures, and tamper detection.

Keep the secret secure

Anyone with the shared secret can generate valid HMAC signatures. Store secrets securely, rotate them regularly, and never expose them in client-side applications.

Guide

About HMAC Generator and Verifier

HMAC combines a cryptographic hash with a shared secret to authenticate message integrity and origin.

This tool generates and verifies HMAC values using SHA-256, SHA-384, or SHA-512.

Anyone who obtains the shared secret can create valid HMACs, so key protection is essential.

Common HMAC uses

HMAC is used when two systems share a secret and need to detect message modification.

  • Webhook signatures
  • API request signing
  • JWT HS256, HS384, and HS512
  • Signed URLs
  • Message-integrity checks

HMAC versus plain hashing

A plain hash proves only that two inputs match. HMAC also requires knowledge of a secret key.

Verification safety

Production implementations should compare authentication codes in constant time to reduce timing side channels.

Secret management

Use strong random secrets, store them securely, rotate exposed values, and separate secrets across environments and integrations.

FAQ

Frequently asked questions

What is HMAC?

HMAC is a keyed message authentication code built from a cryptographic hash and shared secret.

Is HMAC encryption?

No. HMAC provides integrity and authenticity, not confidentiality.

Which HMAC algorithm should I use?

HMAC-SHA-256 is a common default; SHA-384 and SHA-512 are also supported.

Why does verification fail?

The secret, message bytes, algorithm, or output encoding may not match the original signer.

Can I use HMAC for webhook verification?

Yes, if you reproduce the provider's exact signing procedure and compare safely.

Is my secret uploaded?

Generation and verification are intended to run locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.