HMAC Generator
Generate keyed HMAC codes from text or files. Choose SHA-256, SHA-512 or SHA-1, enter a UTF-8 or hex key, and troubleshoot API signature differences locally.
Your result will appear here.
How to calculate an HMAC
- Choose the algorithm required by your integration and enter the message or select a file.
- Enter the key as UTF-8 text, or enable hexadecimal key mode for raw key bytes.
- Calculate and copy the hexadecimal result. For the example below, use hex key 0b repeated 20 times.
Working with HMAC Generator
HMAC combines a message with a secret key to calculate a message authentication code. Both parties must use the same bytes and algorithm. Keep the key secret, and distinguish hexadecimal key bytes from the text spelling of those bytes.
HMAC-SHA-256 example: RFC 4231 test vector
- Input
Input Hi There Algorithm HMAC-SHA-256 Secret key (Key is hexadecimal) 0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b- Result
b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7
Questions about HMAC Generator
Is HMAC the same as SHA-256 or encryption?
No. HMAC uses a shared secret key to authenticate a message; plain SHA-256 has no key. Neither encrypts the message. Output is lowercase hex: 40 characters for SHA-1, 64 for SHA-256 and 128 for SHA-512.
When should I enable hexadecimal key mode?
When the key is represented as hex bytes. 6162 then means the bytes for ab, not the four text characters 6162. Enter complete byte pairs without spaces or a 0x prefix. Base64 keys must be decoded first.
Why does my API or webhook signature differ?
Match the exact message bytes, key and algorithm. Spaces, JSON formatting, line endings and UTF-8 BOM change the result. This calculator does not assemble provider-specific signing strings or convert the result to Base64.
Can I calculate HMAC for a file?
Yes. A selected file takes priority over text, and its original bytes are used. Limits are 8 MiB for text and 32 MiB per file. To reproduce RFC 4231, use message Hi There and hex key 0b repeated 20 times.
Are my files, tokens or text uploaded?
No. These tools process your input in your browser. The website serves the page and its code, but your input is not sent to a conversion server or saved in an account.
Related tools for your next step
- SHA-256 Hash & File Checksum
Generate SHA-256 hashes for text or files and check a downloaded file against its published checksum.
- SHA-512 Hash & File Checksum
Calculate SHA-512 text and file hashes locally and compare full hexadecimal checksums.
- JWT Decoder
Read JWT headers and payloads, inspect expiry and activation times, and view claims without sending your token anywhere.
Explore all developer tools
Encoding & Files
Move between text, bytes, URLs and embedded images without changing your original data.
Base64 Encoder & Decoder
Encode UTF-8 text to Base64 or decode standard and URL-safe Base64. Control padding and line wrapping.
Base64URL Encoder & Decoder
Convert text to URL-safe Base64 with the - and _ alphabet. Encode or decode unpadded Base64URL strings.
Image to Base64
Convert PNG, JPEG, GIF, WebP, SVG and other recognised image files to Base64 Data URIs in your browser.
Base64 to Image
Decode a Base64 image or Data URI, preview supported image types and download the original image bytes.
File to Base64
Encode any file to a Base64 string, with optional Data URI prefix, padding and MIME line wrapping.
Base64 to File
Turn Base64 strings and Data URIs back into downloadable files without changing the decoded binary data.
URL Encoder & Decoder
Encode and decode URL components, complete URLs and form values. Handle percent escapes and spaces correctly.
HTML Entity Encoder & Decoder
Convert text and Unicode characters to HTML entities, or decode named and numeric HTML character references.
Unicode Inspector & Escape Converter
Inspect Unicode code points, UTF-8 bytes and UTF-16 units, or convert JavaScript Unicode escapes to readable text.
Data & Text Inspection
Read structured data, inspect tokens and understand exactly what changed.
JSON Formatter, Minifier & Validator
Format, minify and validate JSON with exact large-number preservation, indentation options and recursive key sorting.
JWT Decoder
Read JWT headers and payloads, inspect expiry and activation times, and view claims without sending your token anywhere.
Text Diff Checker
Compare two texts by line, word or character. Highlight additions and removals while retaining spaces and line breaks.
Regular Expression Tester
Test JavaScript regular expressions with flags, match positions, capture groups and named groups in your browser.
Hashes, IDs & Schedules
Check file integrity, generate identifiers and make sense of times and recurring schedules.
MD5 Hash & File Checksum
Calculate an MD5 hash for text or a local file, and compare it with an expected checksum.
SHA-1 Hash & File Checksum
Calculate SHA-1 hashes for UTF-8 text or files and compare the result with an expected checksum.
SHA-256 Hash & File Checksum
Generate SHA-256 hashes for text or files and check a downloaded file against its published checksum.
SHA-512 Hash & File Checksum
Calculate SHA-512 text and file hashes locally and compare full hexadecimal checksums.
CRC32 Checksum Calculator
Calculate standard CRC-32 checksums for text or files and compare eight-character hexadecimal results.
UUID & GUID Generator
Generate random UUID v4 or time-ordered UUID v7 identifiers, individually or in batches.
Unix Timestamp Converter
Convert Unix seconds, milliseconds and ISO 8601 dates. View the same instant in UTC and any IANA time zone.
Cron Expression Parser
Validate five- or six-field Cron expressions and list upcoming runs in an IANA time zone, including daylight-saving changes.
Cron Expression Generator
Build a Cron expression from time fields or common presets, then preview its next scheduled times in your chosen zone.
Your input and files are processed on your device. Keep sensitive results out of shared clipboards and use a trusted device for private keys and tokens.