What this does
Computes a keyed hash (HMAC, RFC 2104) of a message with HMAC-SHA-1, SHA-256, SHA-384, SHA-512, or SHA3-224/256/384/512. Enter the secret key as text, hex bytes or Base64, and the message as text or raw bytes. The result is shown as hex or Base64.
Verifying a MAC
Paste a received MAC (hex or Base64) into the verify box to see whether it matches the message and key. The comparison looks at every byte whatever the first difference is, so it does not reveal how many leading bytes were right. Use the same approach in your own code:hmac.compare_digest in Python, crypto.timingSafeEqual in Node,hash_equals in PHP. A plain == can leak timing information.
Typical uses
- Checking webhook signatures (GitHub, Stripe and Shopify send an HMAC-SHA-256 of the raw request body). Paste the raw body, not a re-serialised copy.
- Signing and verifying HS256/HS384/HS512 JWTs (see the JWT decoder).
- Authenticating cookies, API requests and download links.
Keys
The key should be random and at least as long as the hash output (32 bytes for SHA-256). The tool warns about empty and short keys. HMAC keys longer than the hash block size are hashed first, which is part of the standard. HMAC-SHA-1 is still a sound MAC even though SHA-1 collisions are practical, but new designs should prefer SHA-256 or better.
Example
Key Jefe, message what do ya want for nothing?, HMAC-SHA-256 gives5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843 (RFC 4231, test case 2).
Privacy
The key and message stay in your browser's memory and are never stored or sent anywhere.