HMAC Generator — Free Online HMAC Authentication Code Generator
Generate HMAC signatures with SHA-256, SHA-512, or SHA-1 — keyed message authentication code for API security.
Jump to tool ↓Frequently Asked Questions
HMAC: Message Authentication with Cryptographic Keys
HMAC (Hash-based Message Authentication Code) solves a fundamental security problem: proving that a message came from someone who knows a shared secret. Unlike regular hashes which are public and deterministic, HMAC output depends on a secret key — without the key, an attacker cannot forge a valid HMAC for any message.
HMAC is foundational to API authentication. AWS Signature Version 4 uses HMAC-SHA256 to sign requests. JWT HS256 tokens use HMAC-SHA256 to sign the header and payload. GitHub, Stripe, and Shopify use HMAC-SHA256 to sign webhook payloads, allowing receiver verification. When you see a signature header like X-Hub-Signature-256: sha256=abc123..., that's HMAC-SHA256.
This tool uses the Web Crypto API (crypto.subtle.importKey +crypto.subtle.sign) for native HMAC computation. Select the algorithm, enter your message and secret key, then click Generate.
Standards & References
Built and maintained by DevDecode. This tool processes your input in your browser; it is not uploaded for processing. Found an issue? Let us know.
Related Tools
Related Guides
What Is a Hash Function? A Plain-English Guide with Examples
A hash function turns any input into a fixed-length string called a hash. Learn how hashing works, the properties of cryptographic hash functions, common algorithms like SHA-256 and MD5, and what hashing is used for.
HashingWhat Is Hashing in Cybersecurity?
Hashing protects passwords and verifies data integrity in cybersecurity. Learn how hashing works, why it's one-way, how salting helps, and how it differs from encryption.
SecurityWhat Is HMAC? How It Works and When to Use It
HMAC (Hash-based Message Authentication Code) proves both data integrity and authenticity. Learn how HMAC works, how it differs from plain hashing, and how to implement it for webhooks and APIs.