HMAC-SHA256/384/512 signatures via native WebCrypto.
🔐 HMAC ≠ hashing: the signature depends on both message and secret, so an attacker cannot forge it without the key. Computed with native WebCrypto — the secret never leaves this page.
SHA-256 alone lets anyone re-compute the digest of a modified message. HMAC folds a secret key into the computation, making forgery infeasible without the key — that is why webhooks use it.
Stripe, GitHub, and Slack sign payloads as HMAC-SHA256 of the raw body with your signing secret. Paste the exact raw body (not re-serialized JSON) and compare the computed hex against the header value.
Same bytes, different encoding. Services differ: Stripe shows hex-style comparisons, AWS SigV4 uses hex, OAuth1 uses base64. This tool gives both so no conversion step is needed.
Short secrets undermine HMAC. Use 32+ random bytes. Rotating a leaked key invalidates old signatures immediately — compute a new expected signature after any rotation before debugging mismatches.
The HMAC Generator creates hmac generator on demand, right in your browser. Set the options you need, click generate, and the result is ready to copy. Because everything runs locally, nothing you enter or produce leaves your device.
Generators like this are useful when you need a specific output (a password, a UUID, a QR code, placeholder text) and don't want to install an app or trust an unknown website with your data. This tool is free, has no usage limits, and works the same on phone and desktop.
Common uses: people reach for this tool when they need to use a verify stripe webhook signature manually, compute hmac sha256 of string, secret key message digest generator, or hmac vs hash difference explained.
Browser-based tools like this one have a few real advantages over installed software or manual methods:
More tools you might find useful