HMAC Generator Online — SHA-256/512, API Signing
Sign a message with a secret key using HMAC-SHA. Choose hex or unpadded base64url output. Runs locally — not a password hash and not for production auth scaffolding.
How HMAC works here
Enter a message and secret key. Choose SHA-256, SHA-384, or SHA-512. The digest updates automatically via Web Crypto. Paste an expected digest to verify a match. HMAC authenticates a message with a shared secret — it is not for storing passwords. Use bcrypt for password hashing.
Options
Examples
Classic vector
Message
HMAC-SHA-256 (hex)
API body
Message
HMAC-SHA-256 (hex)
Related tools
For checksums without a secret use hash-generator. For password storage use bcrypt-hash.
HMAC FAQ
Signing digests
Is HMAC a password hash?
No. HMAC signs a message with a shared secret. For password storage use bcrypt-hash.
Is base64url padded?
No — this tool emits unpadded base64url (no trailing =). Use the base64 output option when the API expects standard padded base64.
My API key is hex or base64, not UTF-8 text. What then?
Set Key encoding to hex or base64 so the secret is decoded to bytes before HMAC. UTF-8 would sign the characters, not the key bytes.
How do I check a digest from my backend?
Paste it in Expected digest. A match means the same message, key bytes, algorithm, and output format.
Does my secret leave the browser?
No. All HMAC computation runs locally via Web Crypto.
Encoding
Encode or decode Base64, URL components and HTML entities — client-side only.
Explore other tool categories
Minify
Shrink code and assets for production — minify JavaScript, CSS, HTML, JSON and XML before gzip or CDN deploy.
Unminify
Expand minified or compressed code — unminify JavaScript, CSS, TypeScript, SCSS, LESS, SQL, YAML and other formats when debugging or reviewing.
Conversion
Transform data between JSON, YAML, XML and CSV locally — no server uploads.
Serialization
Serialize and deserialize PHP data structures beside JSON workflows.
JSON Tools
Validate, format, diff and explore JSON payloads — complementary to minifiers and converters.
SVG Tools
Preview, optimize with SVGO, export Data URI, resize, beautify, convert to JSX and validate SVG — all in your browser.
Beautify
Make code readable with consistent indentation — beautify JavaScript, CSS, TypeScript, SCSS, LESS, Markdown, GraphQL, SQL, YAML and more in your browser.
CSS preprocessors
Compile SCSS or LESS to standard CSS in the browser — pair with beautify or minify for a full stylesheet workflow.
Color & CSS Tools
Paste-local WCAG contrast checking with modern CSS color syntax — pair and matrix views, never uploaded.
DevOps & Infra
Terraform HCL format/validate/minify, Dockerfile format & lint, Docker Compose and .env validation.
CI/CD
GitHub Actions and GitLab CI — format YAML and check workflow/job structure in your browser.
Logs & observability
Line-oriented JSON/NDJSON and Nginx/Apache access logs — format, filter, validate, and CSV/TSV.
Kubernetes
Multi-doc manifests, structural validate, Ingress/Deployment starters, and Helm values formatting.
Networking / IP
CIDR, subnets, and IPv4/IPv6 helpers — in your browser.
Security & tokens
JWKS, X.509 certificates, and secrets scan — browser-local.
API & schemas
OpenAPI tools to format, validate, and lint your specs.
HTTP Tools
Paste-local cURL, HTTP messages, URLs, HAR files, and Cookie / Set-Cookie headers — format and inspect in your browser, never sent.
SEO / Web Tools
Generate meta tags, Open Graph, and Twitter Card output locally — previews simulated from your inputs, never fetched from your live site.
Developer utilities
Timestamps, UUID, ULID, Nanoid, cron, passwords, regex, slugify, number bases, case, text diff, and chmod — all client-side.
Text & Markdown
Count words, build Markdown TOCs, and clean line lists — all in your browser.
AI & LLM
Token counting, pricing estimates, and context-window fit — 100% browser-local.
Test Data
Synthetic field values for fixtures and DB seed — reserved-range phone numbers first.