Generate HMAC authentication codes with SHA-256, SHA-512, or SHA-1. Free browser-based HMAC calculator. 100% free, private, and browser-based — no sign-up.
HMAC (Hash-based Message Authentication Code) combines a cryptographic hash function with a secret key to produce an authentication code. Unlike a plain hash, which anyone can compute, an HMAC can only be generated and verified by parties who possess the secret key. This makes it useful for verifying both the integrity and authenticity of a message.
HMAC was defined in RFC 2104 and is used extensively in internet protocols, API authentication, and message verification systems. It works with any cryptographic hash function — this tool supports SHA-256, SHA-384, SHA-512, and SHA-1.
The HMAC algorithm operates in these steps:
This double-hashing construction provides security even if the underlying hash function has certain weaknesses.
HMAC is a foundational building block in modern security:
SHA-256 is the standard recommendation for most applications. It offers a good balance of security and performance. SHA-512 produces longer hashes and may be faster on modern 64-bit processors. SHA-1 should only be used for legacy compatibility — it has known weaknesses that make it unsuitable for new security applications.
This tool uses the Web Crypto API (crypto.subtle) built into your browser. Neither the message nor the secret key ever leaves your device.
Need to generate a plain hash? Try our SHA-256 Hash Generator. For generating secure keys, check our Password Generator.
HMAC (Hash-based Message Authentication Code) is a mechanism for calculating a message authentication code using a cryptographic hash function combined with a secret key. It verifies both the data integrity and the authenticity of a message.
A regular hash (like SHA-256) only verifies data integrity — anyone can compute it. An HMAC requires a secret key, so only parties who know the key can generate or verify the code. This provides authentication in addition to integrity.
SHA-256 is the most widely used and recommended for most applications. SHA-512 provides a longer output and may be faster on 64-bit systems. SHA-1 is supported for legacy compatibility but is not recommended for new applications.
Yes. All HMAC computation happens in your browser using the Web Crypto API. Neither the message nor the secret key is transmitted to any server.
HMAC is used in API authentication (e.g., AWS Signature), webhook verification (e.g., Stripe, GitHub), JWT token signing, message integrity in TLS/SSL, and many other security protocols.
Browse all free tools · Guides and tutorials · PDF tools · Developer tools · Text tools · SEO tools