HMAC Generator
Sign a message with a secret key and get the HMAC in hex or Base64 — or paste a webhook and see whether its signature is valid, and why not if it isn’t.
At a glance
- Computes HMAC (RFC 2104) with SHA-256, SHA-512, SHA-384, SHA-224, SHA-1, MD5, SHA3-256, SHA3-512, Keccak-256, BLAKE2b and RIPEMD-160 — checked against the RFC 2202 and RFC 4231 test vectors.
- Shows the result as hex, uppercase hex, Base64 and Base64URL, and takes the key and message as text, hex or Base64 — or a file of any size.
- Verifies webhook signatures exactly as GitHub, Stripe, Slack, Shopify, Razorpay, Cashfree, Paddle and Standard Webhooks (Svix, Clerk, Resend) compute them.
- When a signature doesn’t match, it tests the usual causes — wrong algorithm, a trailing line break, re-formatted JSON, spaces around the secret, a hex key typed as text — and offers the fix.
- Gives working code for Node.js, Python, PHP, Java, Go, C# and OpenSSL, with constant-time comparison for webhook checks.
- Keys, secrets and messages stay in your browser and are never saved.
Step by step
How to generate an HMAC
- 1
Pick the algorithm
Choose HMAC-SHA256 unless your API asks for another.
- 2
Enter the secret key
Type or paste the key, or create a random one. Switch to Hex or Base64 if the key is given that way.
- 3
Enter the message
Paste the exact text or payload to sign, or choose a file.
- 4
Copy or compare
Copy the HMAC in the format you need, or paste a signature to check it matches.
Features
Everything you need, nothing you don’t
Webhook debugger
Paste the secret, the signature header and the raw body to see whether the request is genuine.
Explains mismatches
Finds the one change that makes the signature match — so you know whether to fix the body, the secret or the algorithm.
Replay check
Shows how old a webhook timestamp is and warns when providers would reject it as too old.
Every format
Hex, HEX, Base64 and Base64URL side by side; compare with a signature pasted in any of them.
Key advice
Warns about short or empty keys and generates a strong random key in one click.
Copy-paste code
The same HMAC in seven languages, and a ready verify function for each webhook provider.
What an HMAC proves
An HMAC is a hash mixed with a secret key. Anyone with the same key and message gets the same value, and without the key it can’t be forged — so it proves a message came from someone who knows the secret and wasn’t changed on the way.
That’s why payment gateways and platforms sign webhooks with it: your server recomputes the HMAC of the raw body with the shared secret and accepts the request only if it matches the signature header. Compare with a constant-time function (timingSafeEqual, hmac.compare_digest, hash_equals) so the check itself doesn’t leak the signature.
How popular webhooks are signed
| Provider | Header | Signed message | Output |
|---|---|---|---|
| GitHub | X-Hub-Signature-256 | body | sha256=hex |
| Stripe | Stripe-Signature | timestamp.body | t=…,v1=hex |
| Slack | X-Slack-Signature | v0:timestamp:body | v0=hex |
| Shopify | X-Shopify-Hmac-Sha256 | body | Base64 |
| Razorpay | X-Razorpay-Signature | body | hex |
| Razorpay checkout | razorpay_signature | order_id|payment_id | hex |
| Cashfree | x-webhook-signature | timestamp + body | Base64 |
| Standard Webhooks | webhook-signature | id.timestamp.body | v1,Base64 |
FAQ
Frequently asked questions
How do I generate HMAC-SHA256?
Why doesn’t my webhook signature match?
Is HMAC the same as hashing with a salt?
How long should an HMAC key be?
Hex or Base64 — which should I use?
Are my keys sent anywhere?
Keep going
Related tools
Hash Generator
Generate MD5, SHA-1, SHA-256, SHA-512, SHA-3, BLAKE3, CRC32 and HMAC hashes of text or files, and verify checksums. Free, fast and private — no upload.
JWT Encoder
Create and sign JWTs in your browser with HS256, RS256, PS256, ES256 or EdDSA: edit claims, set expiry, generate keys and a JWKS. Keys never leave your device.
Bcrypt Generator & Checker
Generate bcrypt hashes with cost 4–16 and $2a/$2b/$2y prefixes, or check a password against a bcrypt hash. Explains each part. Runs in your browser only.
Base64 Encoder & Decoder
Encode text or files to Base64 and decode Base64 back — UTF-8, URL-safe Base64URL, data URLs for images, file type detection. Free, private, no upload.
Password Generator
Generate strong, random passwords, memorable passphrases and PINs with a cryptographically secure generator. Free, instant and private — nothing is stored.
JSON Formatter & Validator
Format, validate, minify and repair JSON online. Get the exact line and column of every error, a collapsible tree view and sorted keys — private, in-browser.
Last updated Report a problem or suggest a feature