Illustration of a key and a message combining into an HMAC signature

HMAC Generator

Enter a key and a message to compute the HMAC. Runs entirely in your browser — a key is a credential, so nothing here is ever sent anywhere.

Where this actually gets used: webhook verification (GitHub, Stripe, Slack, and most providers sign each webhook payload with an HMAC of a shared secret — e.g. X-Hub-Signature-256 — so the receiver can confirm the request really came from them and wasn't tampered with in transit); API request signing (schemes like AWS Signature V4 sign requests with HMAC instead of, or in addition to, a plain API key); and JWT signing (the HS256/HS384/HS512 algorithms in JSON Web Tokens are literally HMAC-SHA-256/384/512 over the token's header and payload). It's also handy for debugging an integration you're building — compute the HMAC you expect here and compare it against what your own code produces to spot a mismatch quickly.


ℹ️ About HMAC
  • HMAC combines a secret key with a hash function so the result proves both the message's integrity and that whoever produced it knows the key — used for things like signing webhook payloads and API requests.
  • HMAC-MD5 and HMAC-SHA-1 are still used in some legacy systems, but prefer HMAC-SHA-256 or HMAC-SHA-512 for anything new.
  • Runs entirely client-side — nothing you type here is ever sent anywhere. The JSON API below is a separate, opt-in endpoint for scripts.
💻 Show API usage example (cURL)
curl -sS -X POST https://devops.majbase.com/hmac-generator/api \
    -F "key=secret" -F "message=hello world"

Returns {"md5", "sha1", "sha256", "sha512"}, or {"error": "..."}.

🤖 Use this API as a Claude Skill

Want an AI agent (Claude Code, claude.ai, or anything else that supports the Agent Skills format) to use this tool for you on request? Download the skill below and add it:

⬇️ Download SKILL.md · View raw