HMAC Generator

Generate keyed HMAC signatures with many hash functions.

0 chars
SHA-256
SHA-1
SHA-512
SHA-224
SHA-384
SHA-512/256
SHA3-256
SHA3-512
MD5
RIPEMD-160
Whirlpool
HMAC-SHA-256

Result will appear here...

HMAC-SHA-1

Result will appear here...

HMAC-SHA-512

Result will appear here...

HMAC-SHA-224

Result will appear here...

HMAC-SHA-384

Result will appear here...

HMAC-SHA-512/256

Result will appear here...

HMAC-SHA3-256

Result will appear here...

HMAC-SHA3-512

Result will appear here...

HMAC-MD5

Result will appear here...

HMAC-RIPEMD-160

Result will appear here...

HMAC-Whirlpool

Result will appear here...

HMAC Generator

Generate an HMAC (keyed hash) for a message using a secret key. Enter the key and the message and the tool shows HMAC-SHA256, SHA-1, SHA-512, SHA-3, MD5, RIPEMD-160, Whirlpool, and more at once. Everything is computed in your browser.

What HMAC does

HMAC proves that a message was created by someone who holds a shared secret key and that it has not been altered. It is defined in RFC 2104 as H((key ⊕ opad) ‖ H((key ⊕ ipad) ‖ message)), where H is any hash function. Because the key is folded into the hash, an attacker who can see many message/HMAC pairs still cannot forge a valid tag for a new message.

Where HMAC is used

  • API authentication – AWS Signature v4, Stripe and GitHub webhook signatures
  • JWT – the HS256/HS384/HS512 token signatures are HMAC
  • TLS and IPsec – message authentication inside secure channels
  • Password-based key derivation – PBKDF2 uses HMAC internally

Features

  • Secret key as text, hex, or Base64
  • Message as text or file, hashed locally
  • Many hash functions at once; use chips to hide the ones you do not need
  • Hex, uppercase, or Base64 output, plus compare with a known tag

For plain (unkeyed) hashes see the SHA256 Hash Generator. For password storage, which needs a slow algorithm rather than HMAC, see the WordPress Password Hash Generator.

Frequently Asked Questions

HMAC (Hash-based Message Authentication Code, RFC 2104) combines a secret key with a hash function to prove both the integrity and the authenticity of a message. Only someone who knows the key can produce or verify the correct HMAC.

A plain hash can be recomputed by anyone, so it only detects accidental changes. HMAC mixes in a secret key using a specific inner/outer padding scheme, so it detects deliberate tampering and confirms the sender knew the key.

HMAC-SHA256 is the standard default and is widely supported (JWT, AWS signatures, webhooks). Use SHA-512 for a larger tag, or SHA-3 for the newer design. Avoid HMAC-MD5 and HMAC-SHA1 for new systems, though they remain useful for legacy interoperability.

Yes. Set the key type or input type to Hex bytes or Base64 to feed exact binary values — handy when a key is distributed as a hex string rather than a passphrase.

No. The HMAC is computed entirely in your browser; the key and message never leave your device.