HMAC Generator
Sign a message with a secret key or check a webhook signature. Computed with the Web Crypto API — the key never leaves this page.
Runs in your browser — nothing is uploadedSignature
| Hex | — |
|---|---|
| Base64 | — |
How to use HMAC Generator
- Paste the message (for webhooks, the exact raw request body).
- Enter the secret key and choose its encoding and the hash algorithm.
- Copy the signature, or paste an expected signature to verify it.
Questions
Why doesn’t my webhook signature match?
The message must be byte-for-byte identical to what was signed — usually the raw request body before any JSON parsing or reformatting. Also check whether the provider signs a combination such as timestamp + "." + body, and whether it expects hex or Base64.
Is my secret key safe?
The HMAC is computed locally with the Web Crypto API. The key and message are never sent to a server, stored or included in analytics.