Skip to content
ALL DEVELOPER TOOLS56
JSON FormatterTXT → JSONJSON to CSVJSON → CSVCSV to JSONCSV → JSONSQL FormatterSQL → SQLMarkdown to HTMLMD → HTMLHTML to MarkdownHTML → MDXML FormatterXML → XMLBase64 Encode/DecodeTXT → B64URL Encode/DecodeTXT → URLJWT DecoderJWT → JSONHTML Entity Encode/DecodeTXT → HTMLUUID Generator— → UUIDPassword Generator— → TXTHash GeneratorTXT → HASHLorem Ipsum Generator— → TXTQR Code GeneratorTXT → PNGColor Picker & Converter— → HEXCSS Gradient Generator— → CSSBox Shadow Generator— → CSSRegex TesterTXT → MATCHCron Expression GeneratorTXT → CRONTimestamp ConverterNUM → DATEText DiffTXT → DIFFText Case ConverterTXT → TXTWord CounterTXT → STATSSubtitle ConverterSUBS → SRT · VTT · ASSYAML to JSONYAML → JSONJSON to YAMLJSON → YAMLYAML FormatterYAML → YAMLJSON MinifyJSON → JSONSort & Dedupe LinesTXT → TXTLine Ending ConverterTXT → CRLF · LF · CRXLSX to CSVXLSX → CSVCharset ConverterTEXT → UTF-8HAR ViewerHAR → TABLE · HARJWT EncoderJSON → JWTHMAC GeneratorTXT → MACFile ChecksumFILE → VERDICTWi-Fi QR Code Generator— → QRChmod CalculatorOCTAL → RWXHTTP Status CodesCODE → MEANINGByte ConverterSIZE → UNITSTime Zone ConverterTIME → ZONESAspect Ratio CalculatorSIZE → RATIOURL ParserURL → PARTSExtract ArchiveARCHIVE → FILES · ZIPCreate ZIPFILES → ZIPUnzip FilesZIP → FILESDOCX to MarkdownDOCX → MDSVG OptimizerSVG → SVGBarcode Generator— → BARCODEQR Code ReaderIMG → TEXTVCF to CSVVCF → CSVICS to CSVICS → CSVCSV to Markdown TableCSV → MDBcrypt Generator— → HASH
ENGINE SUBTLECRYPTOACCEPTS NONE

HMAC Generator

SUBTLECRYPTOTOOL 156 OF 190

HMAC Generator & Verifier — SHA-1 to SHA-512

Compute an HMAC over a message with a text, hex or base64 key, and check a MAC the other side sent you.

ENGINESUBTLECRYPTO
ACCEPTSNONE
MAX SIZENONE
UPLOADNEVER
01Paste the exact message the MAC covers into the Message pane.
02Enter the SECRET KEY and set Key encoding to match how the key was given to you.
03Copy the Hex or Base64 MAC, or paste the value you were sent into VERIFY to compare it.

About HMAC Generator

An HMAC is a keyed hash: it proves that whoever produced the value held the shared secret, and that the message has not been altered since. It signs webhook deliveries, AWS requests and half the internal APIs you will ever debug. This page computes one with the browser's own Web Crypto, over SHA-1, SHA-256, SHA-384 or SHA-512, and hands it back in hex and base64. The key encoding is a control rather than an assumption, and that is the point. A secret given to you as 64 hex characters is 32 bytes; read as text it is 64, and the two produce unrelated MACs with nothing anywhere to say which one you got. That single mistake is why most people arrive at a tool like this, so it is detected and named on screen. There is a verify field too: paste the value the other side sent — a whole signature header value works, since a leading sha256= is stripped — and it is checked against the hex, base64 and URL-safe spellings of the digest. That comparison is an ordinary string compare, not a constant-time one: fine for diagnosing a failing signature, not something to copy into a server. SHA-1 is offered because legacy APIs still require it.

Questions

My webhook signature never matches and I am sure the key is right.

Then it is probably the encoding, or the message. A secret given as 64 hex characters is 32 bytes, and using those characters as text makes a 64-byte key: same secret, different MAC, no error anywhere. Set the key encoding to match how you were given it, and compare the byte count in the rail with what your library reports. If that is right, the message is the suspect. An HMAC covers exact bytes, so a trailing newline, CRLF line endings, or a JSON body your framework re-serialised with different spacing all change the answer.

Should I use SHA-1? My provider's docs say HMAC-SHA1.

Use it if the other side does — you have no choice, and the situation is better than it sounds. SHA-1's famous weakness is collision resistance, and HMAC does not rest on collision resistance, so HMAC-SHA1 is not broken the way a bare SHA-1 signature is. It is still not something to design around today: for anything new, use SHA-256. The option is here because AWS Signature v2, older provider webhooks and a long tail of internal services still specify it, and a tool that omitted it would be useless for exactly those cases.

Is the verify field safe to copy into my server?

No, and the page says so beside it. The comparison here is an ordinary string compare, which stops as soon as two characters differ — the time it takes to fail leaks roughly how much of the MAC was right, which is enough to reconstruct one guess at a time. A real verifier compares raw bytes in constant time: compare_digest in Python, timingSafeEqual in Node, hash_equals in PHP. This field exists to tell you why a delivery is failing, in a browser, where there is no attacker standing by with a stopwatch.

How is this different from the Hash Generator?

A key. The Hash Generator computes SHA-256 of your data and anyone can recompute it — a fingerprint, good for checking that a download arrived intact. An HMAC folds a secret into the same hash, so only someone holding that secret can produce the value or check it. That is what makes it a signature rather than a checksum: a hash tells you the bytes did not change by accident, an HMAC tells you they were not changed by someone without the key. Different jobs, and the Hash Generator is the one that takes files.

Can I HMAC a file instead of typing a message?

Not here. This page takes text, because the things people sign are text: request bodies, canonical strings, query parameters. The message box is UTF-8, so anything you can type or paste is covered, including CJK and emoji, and the stat strip prints how many bytes actually went in. For a file, the Hash Generator reads one from disk — though it computes unkeyed digests, MD5 and the SHA family, rather than an HMAC. Signing a file's contents with a shared key is not something this page does.

Is my file uploaded to a server?

No. Transmute processes everything locally in your browser using JavaScript and WebAssembly. Your files never leave your device — there is no server, no upload, no cloud processing.

Related