Guides & Blog
ENES
🔏

HMAC Generator & Verifier

cryptoClient-side utility

Compute cryptographic HMAC authentication signatures for webhooks, REST APIs, and message verification using SHA-256, SHA-512, or SHA-1.

✓ 100% In-Browser Execution✓ Free & No Usage Cap✓ Zero Server Data Storage

📖How to Use This Tool

What is HMAC (Hash-Based Message Authentication Code)?

HMAC (defined in RFC 2104) is a specific construction for calculating a message authentication code involving a cryptographic hash function in combination with a shared secret key. It simultaneously verifies both the data integrity and the authenticity of a message.

Unlike raw cryptographic digests (such as standalone SHA-256), which are vulnerable to length-extension attacks, HMAC passes the secret key through internal and external padding operations: $$\text{HMAC}(K, m) = H((K' \oplus opad) \parallel H((K' \oplus ipad) \parallel m))$$

HMAC is the universal backbone for:

  • GitHub, Stripe, Shopify, and Slack webhook signature verification (X-Hub-Signature-256).
  • AWS Signature Version 4 (SigV4) request authentication.
  • JSON Web Signatures (JWS HS256).

How to Use

  1. Select Algorithm: Choose between SHA-256, SHA-512, SHA-384, or legacy SHA-1.
  2. Enter Secret Key: Input your shared secret key string or API signing token.
  3. Enter Payload: Type or paste the exact raw request body or message string.
  4. Generate Signature: Click Generate HMAC to compute both lowercase Hex and Base64 outputs.
  5. Verify Existing Signature: Paste an incoming webhook signature into the verification box to perform a timing-safe match check.

🔗Related Tools in this Category

View all crypto tools →

❓Frequently Asked Questions

Q.Why do webhook providers use HMAC instead of regular hashing?

A plain SHA-256 hash only proves that the body has not been accidentally corrupted. Because anyone can calculate SHA-256, it does not prove who sent it. HMAC incorporates a secret key known only to the sender and recipient, proving that the webhook genuinely originated from the service provider.

Q.Why does my computed webhook signature not match Stripe or GitHub?

The most common cause is whitespace, newline differences (CRLF vs LF), or formatting issues in the payload. Ensure you pass the exact raw HTTP request body bytes before JSON parsing.

Q.What is the difference between Hex and Base64 signatures?

Both represent the identical binary hash digest. Hex uses 16 characters (0-9, a-f) where each byte is 2 hex digits. Base64 uses 64 characters and produces a shorter string. GitHub uses Hex with a sha256= prefix, while AWS and JWTs frequently use Base64.

Explore More Developer Utilities

Browse our full suite of 157 browser-based tools, formatters, converters, and guides.

Read Guides & Blog →