HMAC Signature Generator

Message + secret key → HMAC signature (SHA-256 or SHA-512), computed with WebCrypto and verified against RFC 4231 vectors.

Privacy: signing runs entirely in your browser — the key and message never leave this page.

How to use

  1. Enter the message and the shared secret key — or leave the key empty and Compute generates a random 32-character key for you (the Show button reveals it).
  2. Pick SHA-256 or SHA-512 to match your verifier, then press Compute signature.
  3. Copy the hexadecimal signature — the key is used in memory only and never stored or sent.

Frequently asked questions

What is HMAC for?

It is a keyed hash: authenticating a message. Someone with the same key can verify the signature proves the message was not altered — a plain SHA digest cannot, because anyone can recompute it. APIs use it constantly for signed requests.

Why do I need to keep the key secret?

The signature is only as trustworthy as the key. Anyone holding it can forge valid signatures, so share it only with verifiers. This tool never stores or transmits your key — it exists in the tab only while signing.

SHA-256 or SHA-512 for HMAC?

Either is secure. SHA-256 produces a 64-hex-character signature and is the API default; SHA-512 produces 128 characters and can be faster for long messages on 64-bit hardware. Match whatever your counterpart system expects.

Does this page need HTTPS?

The signing uses the Web Crypto API, which browsers only expose in secure contexts — HTTPS or localhost. This site is served over HTTPS. On an insecure copy of the page you will see a notice instead of a signature.

Is the same message + key always the same signature?

Yes — HMAC is deterministic. That is exactly how verifiers check it: they recompute the signature from the message and their copy of the key, and compare.

Comments