HMAC Generator

Generate HMAC authentication codes with SHA-256, SHA-512, or SHA-1. Free browser-based HMAC calculator. 100% free, private, and browser-based — no sign-up.

How to use

  1. Enter Message — Type or paste the message you want to authenticate
  2. Enter Secret Key — Provide the shared secret key
  3. Get HMAC — Select an algorithm and copy the resulting HMAC

What Is HMAC?

HMAC (Hash-based Message Authentication Code) combines a cryptographic hash function with a secret key to produce an authentication code. Unlike a plain hash, which anyone can compute, an HMAC can only be generated and verified by parties who possess the secret key. This makes it useful for verifying both the integrity and authenticity of a message.

HMAC was defined in RFC 2104 and is used extensively in internet protocols, API authentication, and message verification systems. It works with any cryptographic hash function — this tool supports SHA-256, SHA-384, SHA-512, and SHA-1.

How HMAC Works

The HMAC algorithm operates in these steps:

  • Key preparation: The secret key is padded or hashed to match the hash function's block size
  • Inner hash: The key is XORed with a padding constant, concatenated with the message, and hashed
  • Outer hash: The key is XORed with a different padding constant, concatenated with the inner hash result, and hashed again

This double-hashing construction provides security even if the underlying hash function has certain weaknesses.

Common HMAC Applications

HMAC is a foundational building block in modern security:

  • API authentication: Services like AWS use HMAC-SHA256 to sign API requests, proving the requester possesses the secret key
  • Webhook verification: Platforms like Stripe and GitHub sign webhook payloads with HMAC so receivers can verify the source
  • JWT tokens: JSON Web Tokens signed with HMAC (HS256, HS384, HS512) use the algorithm to ensure token integrity
  • Message integrity: TLS uses HMAC to verify that messages haven't been tampered with during transmission

Choosing an Algorithm

SHA-256 is the standard recommendation for most applications. It offers a good balance of security and performance. SHA-512 produces longer hashes and may be faster on modern 64-bit processors. SHA-1 should only be used for legacy compatibility — it has known weaknesses that make it unsuitable for new security applications.

Privacy

This tool uses the Web Crypto API (crypto.subtle) built into your browser. Neither the message nor the secret key ever leaves your device.

Need to generate a plain hash? Try our SHA-256 Hash Generator. For generating secure keys, check our Password Generator.

Frequently asked questions

What is HMAC?

HMAC (Hash-based Message Authentication Code) is a mechanism for calculating a message authentication code using a cryptographic hash function combined with a secret key. It verifies both the data integrity and the authenticity of a message.

How is HMAC different from a regular hash?

A regular hash (like SHA-256) only verifies data integrity — anyone can compute it. An HMAC requires a secret key, so only parties who know the key can generate or verify the code. This provides authentication in addition to integrity.

Which algorithm should I choose?

SHA-256 is the most widely used and recommended for most applications. SHA-512 provides a longer output and may be faster on 64-bit systems. SHA-1 is supported for legacy compatibility but is not recommended for new applications.

Is my secret key safe?

Yes. All HMAC computation happens in your browser using the Web Crypto API. Neither the message nor the secret key is transmitted to any server.

Where is HMAC used?

HMAC is used in API authentication (e.g., AWS Signature), webhook verification (e.g., Stripe, GitHub), JWT token signing, message integrity in TLS/SSL, and many other security protocols.

Related free tools

  • Password Generator — Generate strong, random passwords with customizable length and character types.
  • MD5 Hash Generator — Generate MD5 hashes from any text. Useful for checksums and data verification.
  • SHA-256 Hash Generator — Generate cryptographic SHA-256 hashes. Industry-standard for security applications.
  • SHA-512 Hash Generator — Generate SHA-512 hashes with 128-character output. Strongest SHA-2 variant.
  • UUID Generator — Generate universally unique identifiers (UUID v4). Cryptographically random.
  • Random String Generator — Generate random alphanumeric or hex strings. Configurable length and quantity.
  • Password Strength Checker — Analyze password strength with entropy score and improvement suggestions.
  • Bcrypt Generator — Generate bcrypt password hashes and verify them against passwords.
  • Credit Card Validator — Check Luhn checksum, detect card type (Visa, Mastercard, Amex, etc.), and verify number length instantly.
  • ROT13 Encoder / Decoder — Apply the ROT13 Caesar cipher or any custom shift. Encoding and decoding are the same operation.
  • Vigenere Cipher — Encrypt and decrypt messages with the classic polyalphabetic Vigenere cipher.
  • Caesar Cipher — Encrypt or decrypt text by shifting each letter by a fixed amount.

Browse all free tools · Guides and tutorials · PDF tools · Developer tools · Text tools · SEO tools