Related tools
- Hash & ChecksumHash text or files with MD5, SHA-1, SHA-256, SHA-384, and SHA-512 at once, and verify the result against a known hash.
- JWT Vulnerability CheckDecode a JWT and test it for alg=none and weak HMAC signing secrets, entirely in your browser.
- TOTP GeneratorGenerate live two-factor authentication codes from a Base32 secret or an otpauth:// URI.
- Bcrypt & Argon2 HasherHash and verify passwords with bcrypt, argon2, and scrypt, entirely in your browser.
- JWT GeneratorBuild, sign, and verify JSON Web Tokens with HS256, RS256, or ES256 locally.
- Password Strength CheckerScore a password's real entropy and crack time, with plain English reasons, on your device.
What it does
Computes an HMAC over a message with a secret key, using SHA-1, SHA-256, SHA-384, or SHA-512, and prints the digest as hex, base64, or base64url. Verify mode goes the other way: paste the MAC a service sent you and it recomputes the digest and compares the two byte by byte, without an early exit, so the comparison itself leaks nothing about how close a wrong value was. It also reports the digest size and the key size, and tells you when a key is too short to be worth much or long enough that HMAC hashes it down first.
How to use it
Type or paste the message into the box, then put the secret key in the Key option, which is masked and never written to the address bar. Pick the algorithm and output encoding your service expects, and switch Key format to hex or base64 if your key is raw bytes rather than text. To check a signature, switch Mode to Verify and paste the MAC you received into the Expected MAC box; it reads hex or base64 either way. The older form still works too: leave the Key option empty and put the key below a line of three dashes in the message box.
Why this one
Every other HMAC calculator asks you to paste a live signing key into a form that posts it to somebody else's server. That key is usually the same one that signs your production webhooks, so pasting it into a random site is a real incident. This one computes the digest with an audited hash library inside the tab: your files and inputs never leave your device, and there is deliberately no curl endpoint for it. MD5 is not offered, because an HMAC-MD5 calculator is only ever used to keep a broken integration limping.
FAQ
- Does the key end up in the URL when I share a link?
- No. Option values are normally stored in the page URL so a link can carry your settings, but the Key option is flagged as a secret: it is masked on screen, it is never written to the address bar, and a link that tries to pre-fill it is ignored. The message box is kept out of the URL as well, because it still accepts the older form where the key is typed below a line of three or more dashes.
- My webhook signature does not match. What is usually wrong?
- Four things, in order of how often they cause it. The message has to be the exact raw request body, byte for byte, before any JSON parsing or re-serializing. Some providers sign a constructed string rather than the body alone, for example a timestamp, a period, and then the body. The key may be raw bytes issued as hex or base64 rather than text, in which case set Key format to match. And the encoding of the digest itself may be base64 where you assumed hex.
- Is HMAC-SHA1 still safe to use?
- For authentication, yes in practice: the known SHA-1 attacks are collision attacks, and HMAC does not depend on collision resistance the way a plain signature does, so HMAC-SHA1 has not been broken. It is still offered here because plenty of older APIs, including AWS Signature Version 2, use it and you need to be able to debug them. For anything new, use SHA-256.
- Does the key or the message get uploaded anywhere?
- No. The digest is computed in JavaScript inside your browser tab, so your files and inputs never leave your device, and the page keeps working offline after the first load. This tool has no server endpoint at all, precisely because a hosted HMAC endpoint would mean real signing keys traveling over the network.
Keyboard shortcuts: press ? anywhere on this page to see them.