HMAC Generator Online — SHA-256/512, API Signing

Sign a message with a secret key using HMAC-SHA. Choose hex or unpadded base64url output. Runs locally — not a password hash and not for production auth scaffolding.

Loading…
HMAC generator — API signing digests
Compute HMAC-SHA digests from a message and secret. Hex, base64, or unpadded base64url. Not a password hash.

How HMAC works here

Enter a message and secret key. Choose SHA-256, SHA-384, or SHA-512. The digest updates automatically via Web Crypto. Paste an expected digest to verify a match. HMAC authenticates a message with a shared secret — it is not for storing passwords. Use bcrypt for password hashing.

Options

Algorithm
HMAC-SHA-256 (default), SHA-384, or SHA-512 — native Web Crypto set.
Output
hex for headers/checksums; unpadded base64url for compact tokens; standard padded base64 for APIs that expect it.
Uppercase hex
Applies only when output is hex. Ignored for base64 and base64url.
Key encoding
How the secret is decoded before HMAC: UTF-8 text (default), hex bytes, or base64 / base64url bytes.
Verify digest
Paste an expected digest. Comparison ignores hex case and spaces, and base64url padding.

Examples

Classic vector

Message

POST /v1/orders HTTP/1.1 host: api.example.test content-type: application/json x-request-id: fm-demo-hmac-signing-fixture-001 {"id":42,"total":19.99,"currency":"USD","items":[{"sku":"FM-001","qty":2}]} # Fixture body for FastMinify HMAC generator sample (not a real request)

HMAC-SHA-256 (hex)

600cc1f2dd302d203d9a41acdcfd2a2a195e6f5a34da12b55af6d1c27e6d9941

API body

Message

{"id":42}

HMAC-SHA-256 (hex)

Digest with your shared secret (SHA-256 hex by default)

Related tools

For checksums without a secret use hash-generator. For password storage use bcrypt-hash.

HMAC FAQ

Signing digests

Is HMAC a password hash?

No. HMAC signs a message with a shared secret. For password storage use bcrypt-hash.

Is base64url padded?

No — this tool emits unpadded base64url (no trailing =). Use the base64 output option when the API expects standard padded base64.

My API key is hex or base64, not UTF-8 text. What then?

Set Key encoding to hex or base64 so the secret is decoded to bytes before HMAC. UTF-8 would sign the characters, not the key bytes.

How do I check a digest from my backend?

Paste it in Expected digest. A match means the same message, key bytes, algorithm, and output format.

Does my secret leave the browser?

No. All HMAC computation runs locally via Web Crypto.

Encoding

Encode or decode Base64, URL components and HTML entities — client-side only.

Explore other tool categories

Minify

Shrink code and assets for production — minify JavaScript, CSS, HTML, JSON and XML before gzip or CDN deploy.

Unminify

Expand minified or compressed code — unminify JavaScript, CSS, TypeScript, SCSS, LESS, SQL, YAML and other formats when debugging or reviewing.

Conversion

Transform data between JSON, YAML, XML and CSV locally — no server uploads.

Serialization

Serialize and deserialize PHP data structures beside JSON workflows.

JSON Tools

Validate, format, diff and explore JSON payloads — complementary to minifiers and converters.

SVG Tools

Preview, optimize with SVGO, export Data URI, resize, beautify, convert to JSX and validate SVG — all in your browser.

Beautify

Make code readable with consistent indentation — beautify JavaScript, CSS, TypeScript, SCSS, LESS, Markdown, GraphQL, SQL, YAML and more in your browser.

CSS preprocessors

Compile SCSS or LESS to standard CSS in the browser — pair with beautify or minify for a full stylesheet workflow.

Color & CSS Tools

Paste-local WCAG contrast checking with modern CSS color syntax — pair and matrix views, never uploaded.

DevOps & Infra

Terraform HCL format/validate/minify, Dockerfile format & lint, Docker Compose and .env validation.

CI/CD

GitHub Actions and GitLab CI — format YAML and check workflow/job structure in your browser.

Logs & observability

Line-oriented JSON/NDJSON and Nginx/Apache access logs — format, filter, validate, and CSV/TSV.

Kubernetes

Multi-doc manifests, structural validate, Ingress/Deployment starters, and Helm values formatting.

Networking / IP

CIDR, subnets, and IPv4/IPv6 helpers — in your browser.

Security & tokens

JWKS, X.509 certificates, and secrets scan — browser-local.

API & schemas

OpenAPI tools to format, validate, and lint your specs.

HTTP Tools

Paste-local cURL, HTTP messages, URLs, HAR files, and Cookie / Set-Cookie headers — format and inspect in your browser, never sent.

SEO / Web Tools

Generate meta tags, Open Graph, and Twitter Card output locally — previews simulated from your inputs, never fetched from your live site.

Developer utilities

Timestamps, UUID, ULID, Nanoid, cron, passwords, regex, slugify, number bases, case, text diff, and chmod — all client-side.

Text & Markdown

Count words, build Markdown TOCs, and clean line lists — all in your browser.

AI & LLM

Token counting, pricing estimates, and context-window fit — 100% browser-local.

Test Data

Synthetic field values for fixtures and DB seed — reserved-range phone numbers first.