HMAC Generator

Sign a message with a secret key or check a webhook signature. Computed with the Web Crypto API — the key never leaves this page.

Runs in your browser — nothing is uploaded
Algorithm

Signature

Hex—
Base64—

How to use HMAC Generator

  1. Paste the message (for webhooks, the exact raw request body).
  2. Enter the secret key and choose its encoding and the hash algorithm.
  3. Copy the signature, or paste an expected signature to verify it.

Questions

Why doesn’t my webhook signature match?

The message must be byte-for-byte identical to what was signed — usually the raw request body before any JSON parsing or reformatting. Also check whether the provider signs a combination such as timestamp + "." + body, and whether it expects hex or Base64.

Is my secret key safe?

The HMAC is computed locally with the Web Crypto API. The key and message are never sent to a server, stored or included in analytics.