๐ HMAC Calculator
Enter a secret key
Enter a secret key and a message to compute an HMAC (keyed-hash message authentication code) live in your browser. Supports SHA-1, SHA-256, SHA-384, and SHA-512. All computation happens via the Web Crypto API and never leaves your browser.
How to use
- Enter a secret key.
- Enter the message to sign.
- Select a hash algorithm.
- The HMAC value is shown automatically in both hex and Base64.
How the calculation works
HMAC (hash-based message authentication code), defined in RFC 2104, combines a secret key with a hash function to prove that a message has not been altered and was produced by someone holding the key. HMAC(K, m) = H((K โ opad) โ H((K โ ipad) โ m)) K is the key, m the message, H the hash function (such as SHA-256), and ipad and opad are fixed padding values. Hashing twice this way is much safer than simply hashing "key + message". This tool encodes the key and message as UTF-8, computes HMAC-SHA1, SHA-256, SHA-384 or SHA-512 with the browser's Web Crypto API, and shows the result in hex and Base64. Results have been checked against the RFC 4231 test cases.
Worked example
RFC 4231 test case 2 Key: Jefe Message: what do ya want for nothing? HMAC-SHA256: 5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843 Default (key mysecretkey, message The quick brown fox, SHA-256) 0062435a191760a5e4c7b02ebc6f1a08333a97bb2c0ec28b22c93dbfa1006f07
Things to be aware of
- When verifying webhook or API signatures, a single different newline or space changes the result completely. Make sure the signed string matches exactly.
- If your key is given in hex or Base64, this calculator treats it as a UTF-8 string, so the results will not match.
- When comparing signatures in code, use a constant-time comparison so timing differences do not leak information.
FAQ
What is HMAC?
A mechanism that combines a secret key with a hash function to simultaneously detect tampering and authenticate the sender of a message. Itโs used for signing API requests, verifying webhooks, and similar tasks.
Is this calculation correct?
It has been verified against the official HMAC-SHA256 test vectors defined in RFC 4231, and cross-checked against Node.jsโs standard cryptography library.
How is this different from a plain hash (like SHA-256)?
Anyone can compute a plain hash, but only someone holding the secret key can compute or verify a correct HMAC โ making it suitable for authentication and message-authenticity checks.