Skip to content
UniKit

HMAC generator

Compute HMAC signatures with a secret key using MD5, SHA-1, SHA-256 or SHA-512, with the key read as UTF-8 text or hex, and output as hex or Base64.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

Key interpretation
Digest length: 32 bytes
HMAC result
Hex
Base64

Matches node crypto.createHmac — handy for verifying server-side signatures

What this tool does

  • Verify a server-side signature: enter the message and secret, then compare the HMAC with the value in your logs to tell a wrong key from a tampered payload.
  • Work out signatures for payments, webhooks or open-platform APIs: HMAC-MD5/SHA-1/SHA-256/SHA-512, returned as both hex and Base64.
  • Skip the text conversion when the key is binary: switch the key interpretation to hex and paste a 32-character hex secret directly.
  • Use it as an RFC 2104 reference implementation — the output matches node crypto.createHmac, so you can validate your own code against it.

Example

Input

Message "what do ya want for nothing?", secret "Jefe" (UTF-8), HMAC-SHA-256

Output

Hex: 5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843
Base64: W9zBRr9gdU5qBCQmCJV1x1oAPwidJzmDnexYuWTsOEM=

This is the classic RFC 4231 test vector; switching to SHA-1 gives b34ceac4516ff23a143e61d79d0fa7a4fbe5f266 and MD5 gives 04130747afca4d79e32e87cf2104f087.

Frequently asked questions

How is HMAC different from hashing the message directly?

A plain hash can be computed by anyone, so it cannot prove the message came from a key holder. HMAC mixes the key into two rounds of hashing, so only someone with the key can produce the same value — that gives you both integrity and authenticity.

Which algorithm should I choose?

Use HMAC-SHA-256 for new systems: strong enough and available everywhere. SHA-512 is more conservative but produces longer output. HMAC-MD5 and HMAC-SHA-1 have no practical forgery attack today, but when the other side supports it, prefer SHA-256 or stronger.

Why can the secret be interpreted as hex?

Many platforms use binary secrets transported as hex strings (32 hex characters meaning a 16-byte key). Interpreting those same 32 characters as UTF-8 changes both the key length and its contents, so the signature can never match — hence the two interpretation modes.

What are the three most common reasons a signature does not match?

The key interpretation is wrong (UTF-8 versus hex), the signed message differs by a newline or space, or the output encoding differs (hex case, Base64 padding). Align those three before suspecting the algorithm.

Are the secret and message uploaded?

No. All four algorithms are synchronous pure JavaScript implementations running locally, the page makes no requests, and the secret never leaves your device.

Keywords:hmacsha256sha1md5签名signature密钥secretapi 签名rfc 2104

Related tools