HMAC Generator
Generate keyed HMAC signatures with many hash functions.
HMAC-SHA-256
Result will appear here...
HMAC-SHA-1
Result will appear here...
HMAC-SHA-512
Result will appear here...
HMAC-SHA-224
Result will appear here...
HMAC-SHA-384
Result will appear here...
HMAC-SHA-512/256
Result will appear here...
HMAC-SHA3-256
Result will appear here...
HMAC-SHA3-512
Result will appear here...
HMAC-MD5
Result will appear here...
HMAC-RIPEMD-160
Result will appear here...
HMAC-Whirlpool
Result will appear here...
HMAC Generator
Generate an HMAC (keyed hash) for a message using a secret key. Enter the key and the message and the tool shows HMAC-SHA256, SHA-1, SHA-512, SHA-3, MD5, RIPEMD-160, Whirlpool, and more at once. Everything is computed in your browser.
What HMAC does
HMAC proves that a message was created by someone who holds a shared secret key and that it has not been altered. It is defined in RFC 2104 as H((key ⊕ opad) ‖ H((key ⊕ ipad) ‖ message)), where H is any hash function. Because the key is folded into the hash, an attacker who can see many message/HMAC pairs still cannot forge a valid tag for a new message.
Where HMAC is used
- API authentication – AWS Signature v4, Stripe and GitHub webhook signatures
- JWT – the HS256/HS384/HS512 token signatures are HMAC
- TLS and IPsec – message authentication inside secure channels
- Password-based key derivation – PBKDF2 uses HMAC internally
Features
- Secret key as text, hex, or Base64
- Message as text or file, hashed locally
- Many hash functions at once; use chips to hide the ones you do not need
- Hex, uppercase, or Base64 output, plus compare with a known tag
Related tools
For plain (unkeyed) hashes see the SHA256 Hash Generator. For password storage, which needs a slow algorithm rather than HMAC, see the WordPress Password Hash Generator.
Frequently Asked Questions
What is an HMAC?
HMAC (Hash-based Message Authentication Code, RFC 2104) combines a secret key with a hash function to prove both the integrity and the authenticity of a message. Only someone who knows the key can produce or verify the correct HMAC.
How is HMAC different from a plain hash?
A plain hash can be recomputed by anyone, so it only detects accidental changes. HMAC mixes in a secret key using a specific inner/outer padding scheme, so it detects deliberate tampering and confirms the sender knew the key.
Which hash should I pick for HMAC?
HMAC-SHA256 is the standard default and is widely supported (JWT, AWS signatures, webhooks). Use SHA-512 for a larger tag, or SHA-3 for the newer design. Avoid HMAC-MD5 and HMAC-SHA1 for new systems, though they remain useful for legacy interoperability.
Can I enter the key or message as hex?
Yes. Set the key type or input type to Hex bytes or Base64 to feed exact binary values — handy when a key is distributed as a hex string rather than a passphrase.
Is my key sent anywhere?
No. The HMAC is computed entirely in your browser; the key and message never leave your device.