HMAC Generator Online — SHA-256, SHA-384, SHA-512

Sign a message with a secret key using HMAC-SHA. Choose hex or unpadded base64url output. Runs locally — not a password hash and not for production auth scaffolding.

Loading…
HMAC generator — API signing digests
Compute HMAC-SHA digests from a message and secret. Hex or unpadded base64url. Not a password hash.

How HMAC works here

Enter a message and secret key. Choose SHA-256, SHA-384, or SHA-512. The digest updates automatically via Web Crypto. HMAC authenticates a message with a shared secret — it is not for storing passwords. Use bcrypt for password hashing.

Options

Algorithm
HMAC-SHA-256 (default), SHA-384, or SHA-512 — native Web Crypto set.
Output
hex for headers/checksums; base64url unpadded for compact tokens.
Uppercase hex
Applies only when output is hex. Ignored for base64url.

Examples

Classic vector

Message

POST /v1/orders HTTP/1.1 host: api.example.test content-type: application/json x-request-id: fm-demo-hmac-signing-fixture-001 {"id":42,"total":19.99,"currency":"USD","items":[{"sku":"FM-001","qty":2}]} # Fixture body for FastMinify HMAC generator sample (not a real request)

HMAC-SHA-256 (hex)

600cc1f2dd302d203d9a41acdcfd2a2a195e6f5a34da12b55af6d1c27e6d9941

API body

Message

{"id":42}

HMAC-SHA-256 (hex)

Digest with your shared secret (SHA-256 hex by default)

Related tools

For checksums without a secret use hash-generator. For password storage use bcrypt-hash.

HMAC FAQ

Signing digests

Is HMAC a password hash?

No. HMAC signs a message with a shared secret. For password storage use bcrypt-hash.

Is base64url padded?

No — this tool emits unpadded base64url (no trailing =).

Does my secret leave the browser?

No. All HMAC computation runs locally via Web Crypto.

Encoding

Encode or decode Base64, URL components and HTML entities — client-side only.

Explore other tool categories

Minify

Shrink code and assets for production — minify JavaScript, CSS, HTML, JSON and XML before gzip or CDN deploy.

Beautify

Make code readable with consistent indentation — beautify JavaScript, CSS, TypeScript, SCSS, LESS, Markdown, GraphQL, SQL, YAML and more in your browser.

Unminify

Expand minified or compressed code — unminify JavaScript, CSS, TypeScript, SCSS, LESS, SQL, YAML and other formats when debugging or reviewing.

Conversion

Transform data between JSON, YAML, XML and CSV locally — no server uploads.

CSS preprocessors

Compile SCSS or LESS to standard CSS in the browser — pair with beautify or minify for a full stylesheet workflow.

JSON Tools

Validate, format, diff and explore JSON payloads — complementary to minifiers and converters.

SVG Tools

Preview, optimize with SVGO, export Data URI, resize, beautify, convert to JSX and validate SVG — all in your browser.

DevOps & Infra

Terraform HCL format/validate/minify, Dockerfile format & lint, Docker Compose and .env validation.

CI/CD

GitHub Actions and GitLab CI — format YAML and check workflow/job structure in your browser.

Logs & observability

Line-oriented JSON/NDJSON and Nginx/Apache access logs — format, filter, validate, and CSV/TSV.

Kubernetes

Multi-doc manifests, structural validate, Ingress/Deployment starters, and Helm values formatting.

Networking / IP

CIDR, subnets, and IPv4/IPv6 helpers — in your browser.

Security & tokens

JWKS, X.509 certificates, and secrets scan — browser-local.

API & schemas

OpenAPI tools to format, validate, and lint your specs.

Developer utilities

Timestamps, UUID, ULID, Nanoid, cron, passwords, regex, slugify, number bases, case, text diff, and chmod — all client-side.

Text & Markdown

Count words, build Markdown TOCs, and clean line lists — all in your browser.

AI & LLM

Token counting, pricing estimates, and context-window fit — 100% browser-local.

Serialization

Serialize and deserialize PHP data structures beside JSON workflows.