HMAC Generator
Create HMAC-SHA256/384/512 message authentication codes from a secret key.
The HMAC Generator creates message authentication codes using HMAC-SHA256, SHA384, and SHA512, which let a receiver who shares your secret key confirm that a message was not altered and really came from you. This is the technique behind signing API requests and verifying webhooks. Enter a message and a secret and the tool produces the HMAC as a hex digest. It is useful when you are configuring an API that requires request signatures, debugging why a signature check failed, or comparing the output of two implementations. HMAC is the proper construction for combining a hash with a secret; do not substitute a naive hash of secret plus message. A message authentication code answers two questions at once: did the message arrive unchanged, and did it come from someone who holds the shared secret. The construction that does this safely is HMAC, which feeds a key into a hash function in a specific nested way rather than simply concatenating the secret with the message. That detail matters because the naive approach of hashing the secret plus the message is vulnerable to length extension attacks, where an attacker who sees one valid tag can compute a valid tag for an extended message without learning the key. HMAC avoids this, which is why it underpins the request signing schemes used by payment APIs, cloud services, and webhook delivery. The everyday use is straightforward: you hold a secret and a message, compute the tag, and send it alongside. The receiver repeats the computation and compares. When a signature check fails, the fastest diagnosis is to compute the expected tag on both sides and compare the inputs, because the mismatch is nearly always in the exact bytes of the message or in the secret rather than in the algorithm.
Result appears here.
Frequently Asked Questions
What is HMAC used for?
HMAC proves both integrity and authenticity of a message using a shared secret — a receiver with the same key can confirm the data was not altered and came from you.
SHA-256 vs SHA-512 for HMAC?
Both are secure; SHA-512 is marginally stronger and faster on 64-bit systems. Use SHA-256 unless you have a specific compliance reason for 512.
Is HMAC the same as hashing a secret + message?
No. Naively concatenating secret+message is vulnerable to length-extension attacks; HMAC applies the hash twice in a specific construction to avoid that.