HMAC Generator & Verifier
Compute cryptographic HMAC authentication signatures for webhooks, REST APIs, and message verification using SHA-256, SHA-512, or SHA-1.
Compute cryptographic HMAC authentication signatures for webhooks, REST APIs, and message verification using SHA-256, SHA-512, or SHA-1.
HMAC (defined in RFC 2104) is a specific construction for calculating a message authentication code involving a cryptographic hash function in combination with a shared secret key. It simultaneously verifies both the data integrity and the authenticity of a message.
Unlike raw cryptographic digests (such as standalone SHA-256), which are vulnerable to length-extension attacks, HMAC passes the secret key through internal and external padding operations: $$\text{HMAC}(K, m) = H((K' \oplus opad) \parallel H((K' \oplus ipad) \parallel m))$$
HMAC is the universal backbone for:
X-Hub-Signature-256).Generate and verify Blowfish-based Bcrypt cryptographic password hashes with configurable cost factors completely inside your browser.
Generate standard 2048-bit and 4096-bit RSA key pairs in your browser using the Web Crypto API. Export clean PEM files for SSH, JWT, or SSL/TLS.
Encrypt sensitive text or payloads with military-grade AES-256-GCM or AES-CBC authenticated ciphers. Decrypt payloads using matching passphrases locally.
Generate and verify standard 30-second Two-Factor Authentication (2FA) TOTP codes from Base32 secrets. Compatible with Google Authenticator, Authy, and 1Password.
A plain SHA-256 hash only proves that the body has not been accidentally corrupted. Because anyone can calculate SHA-256, it does not prove who sent it. HMAC incorporates a secret key known only to the sender and recipient, proving that the webhook genuinely originated from the service provider.
The most common cause is whitespace, newline differences (CRLF vs LF), or formatting issues in the payload. Ensure you pass the exact raw HTTP request body bytes before JSON parsing.
Both represent the identical binary hash digest. Hex uses 16 characters (0-9, a-f) where each byte is 2 hex digits. Base64 uses 64 characters and produces a shorter string. GitHub uses Hex with a sha256= prefix, while AWS and JWTs frequently use Base64.
Browse our full suite of 157 browser-based tools, formatters, converters, and guides.