Enter a key and a message to compute the HMAC. Runs entirely in your browser — a key is a credential, so nothing here is ever sent anywhere.
Where this actually gets used: webhook verification (GitHub, Stripe, Slack, and most providers sign each webhook payload with an HMAC of a shared secret — e.g. X-Hub-Signature-256 — so the receiver can confirm the request really came from them and wasn't tampered with in transit); API request signing (schemes like AWS Signature V4 sign requests with HMAC instead of, or in addition to, a plain API key); and JWT signing (the HS256/HS384/HS512 algorithms in JSON Web Tokens are literally HMAC-SHA-256/384/512 over the token's header and payload). It's also handy for debugging an integration you're building — compute the HMAC you expect here and compare it against what your own code produces to spot a mismatch quickly.
curl -sS -X POST https://devops.majbase.com/hmac-generator/api \
-F "key=secret" -F "message=hello world"
Returns {"md5", "sha1", "sha256", "sha512"}, or {"error": "..."}.
Want an AI agent (Claude Code, claude.ai, or anything else that supports the Agent Skills format) to use this tool for you on request? Download the skill below and add it:
~/.claude/skills/hmac-generator/SKILL.md