HMAC Generator Online (MD5 to SHA-512) — Free
Runs 100% in your browser — your files never leave your device.
HMACs prove a message came from someone holding a shared secret — the backbone of webhook signatures and API authentication. Paste your text, enter the secret key, pick an algorithm from MD5 through SHA-512, and copy the signature. The secret never leaves your browser.
How it works
- 1
Enter text and secret
Paste the message to sign and the shared secret key.
- 2
Pick an algorithm
HMAC-MD5 through HMAC-SHA-512 are all supported.
- 3
Copy the signature
One click copies the hex signature for your API or webhook.
About this tool
What HMAC adds to a hash
A plain hash can be computed by anyone; an HMAC binds the hash to a secret key only you and the counterpart share. The result proves both that the message is unchanged and that whoever produced it held the key — the backbone of webhook signatures and API authentication.
The verification workflow
The sender computes the HMAC of the message with the shared secret and sends both. You compute the HMAC of what you received with your copy of the secret and compare — a match proves integrity and origin. Every webhook provider (Stripe, GitHub, Slack) documents this exact flow.
Compare safely
Comparing HMACs with a plain string equality check can leak timing information that helps attackers forge signatures — constant-time comparison is the standard defense, and the tool compares the way verification libraries do.
Frequently asked questions
What is the secret key?
A shared string agreed between you and the other party — often issued by the API provider in their dashboard. Anyone holding it can forge valid signatures, so it is as sensitive as a password.
Which hash algorithm should the HMAC use?
SHA-256 is the ecosystem default; SHA-384 and SHA-512 appear in stricter integrations. Match whatever the API you are integrating specifies.
Why does my webhook signature not match?
The usual culprits: signing the parsed body instead of the raw bytes, a wrong secret, or a timestamp prefix the provider includes. HMAC is exact — one byte of difference changes everything.