Skip to content
JustTools

HMAC Generator

Sign a message with a secret key and get the HMAC in hex or Base64 — or paste a webhook and see whether its signature is valid, and why not if it isn’t.

Runs in your browser Free · no sign-up

At a glance

  • Computes HMAC (RFC 2104) with SHA-256, SHA-512, SHA-384, SHA-224, SHA-1, MD5, SHA3-256, SHA3-512, Keccak-256, BLAKE2b and RIPEMD-160 — checked against the RFC 2202 and RFC 4231 test vectors.
  • Shows the result as hex, uppercase hex, Base64 and Base64URL, and takes the key and message as text, hex or Base64 — or a file of any size.
  • Verifies webhook signatures exactly as GitHub, Stripe, Slack, Shopify, Razorpay, Cashfree, Paddle and Standard Webhooks (Svix, Clerk, Resend) compute them.
  • When a signature doesn’t match, it tests the usual causes — wrong algorithm, a trailing line break, re-formatted JSON, spaces around the secret, a hex key typed as text — and offers the fix.
  • Gives working code for Node.js, Python, PHP, Java, Go, C# and OpenSSL, with constant-time comparison for webhook checks.
  • Keys, secrets and messages stay in your browser and are never saved.

Step by step

How to generate an HMAC

  1. 1

    Pick the algorithm

    Choose HMAC-SHA256 unless your API asks for another.

  2. 2

    Enter the secret key

    Type or paste the key, or create a random one. Switch to Hex or Base64 if the key is given that way.

  3. 3

    Enter the message

    Paste the exact text or payload to sign, or choose a file.

  4. 4

    Copy or compare

    Copy the HMAC in the format you need, or paste a signature to check it matches.

Features

Everything you need, nothing you don’t

Webhook debugger

Paste the secret, the signature header and the raw body to see whether the request is genuine.

Explains mismatches

Finds the one change that makes the signature match — so you know whether to fix the body, the secret or the algorithm.

Replay check

Shows how old a webhook timestamp is and warns when providers would reject it as too old.

Every format

Hex, HEX, Base64 and Base64URL side by side; compare with a signature pasted in any of them.

Key advice

Warns about short or empty keys and generates a strong random key in one click.

Copy-paste code

The same HMAC in seven languages, and a ready verify function for each webhook provider.

What an HMAC proves

An HMAC is a hash mixed with a secret key. Anyone with the same key and message gets the same value, and without the key it can’t be forged — so it proves a message came from someone who knows the secret and wasn’t changed on the way.

That’s why payment gateways and platforms sign webhooks with it: your server recomputes the HMAC of the raw body with the shared secret and accepts the request only if it matches the signature header. Compare with a constant-time function (timingSafeEqual, hmac.compare_digest, hash_equals) so the check itself doesn’t leak the signature.

How popular webhooks are signed

ProviderHeaderSigned messageOutput
GitHubX-Hub-Signature-256bodysha256=hex
StripeStripe-Signaturetimestamp.bodyt=…,v1=hex
SlackX-Slack-Signaturev0:timestamp:bodyv0=hex
ShopifyX-Shopify-Hmac-Sha256bodyBase64
RazorpayX-Razorpay-Signaturebodyhex
Razorpay checkoutrazorpay_signatureorder_id|payment_idhex
Cashfreex-webhook-signaturetimestamp + bodyBase64
Standard Webhookswebhook-signatureid.timestamp.bodyv1,Base64

FAQ

Frequently asked questions

How do I generate HMAC-SHA256?

Keep HMAC-SHA256 selected, enter the secret key and the message. The HMAC appears instantly in hex and Base64 — copy the one your API expects.

Why doesn’t my webhook signature match?

Almost always because the body was changed before hashing — parsed and re-serialised JSON, a trailing newline, or different line breaks. Sign the raw bytes exactly as received. The second most common cause is the wrong secret, such as an API key instead of the webhook secret. This tool checks these for you.

Is HMAC the same as hashing with a salt?

No. HMAC uses the key in a special two-pass construction that stays secure even with hashes like MD5 or SHA-1. Simply hashing key + message is open to length-extension attacks. For passwords, use bcrypt or Argon2 instead — see the Bcrypt Generator & Checker.

How long should an HMAC key be?

At least as long as the hash output — 32 random bytes for HMAC-SHA256. Keys longer than the block size (64 bytes for SHA-256) are hashed first, so they add nothing.

Hex or Base64 — which should I use?

They are the same bytes written differently. Use whatever the other side expects: GitHub, Stripe and Razorpay use hex; Shopify, Cashfree and Standard Webhooks use Base64.

Are my keys sent anywhere?

No. Everything is computed in your browser, and keys, secrets and messages are not saved — only your algorithm and provider choice are remembered.

Keep going

Browse every tool

Last updated Report a problem or suggest a feature