HMAC Generator
Generate an HMAC signature for a message and secret key using SHA-1, SHA-256, SHA-384 or SHA-512, via the Web Crypto API. Runs in your browser.
How to use HMAC Generator: Open HMAC Generator — it runs entirely in your browser with no setup. Paste or type your input into the text area, or upload a file where supported. Set any options you need. The result appears in the output panel — there is no upload step and no waiting on a server. Everything runs inside your browser, so your data never leaves your device.
Generate an HMAC signature for a message and secret key using SHA-1, SHA-256, SHA-384 or SHA-512, via the Web Crypto API. Runs in your browser. HMAC Generator is a free, browser-based tool in the Filevane developer tools collection — there is nothing to install, no account to create and no watermark on your results. It works on desktop, tablet and mobile, and because the work happens on your own device it stays fast even with large inputs.
How to use HMAC Generator
- Open HMAC Generator — it runs entirely in your browser with no setup.
- Paste or type your input into the text area, or upload a file where supported.
- Set any options you need. The result appears in the output panel — there is no upload step and no waiting on a server.
- Review the output instantly; large inputs are handled locally without lag.
- Copy the result to your clipboard or download it. Your data never leaves the page.
Why use HMAC Generator?
- 100% free with no limits, no sign-up and no watermarks.
- Private by design — your data are processed in your browser and never uploaded to a server.
- Fast and lightweight, with instant results even on a phone or a slow connection.
- Works everywhere — any modern browser on Windows, macOS, Linux, Android or iOS.
- Part of a full developer tools suite, so related hmac tasks are one click away.
What people use HMAC Generator for
- Verifying a webhook signature from Stripe, GitHub or a payment provider.
- Generating a signature for an API that requires request signing.
- Checking that a signed value has not been tampered with in transit.
HMAC Generator: limits and things worth knowing
- An HMAC is not a plain hash of the key plus the message. It uses the key twice in a specific nested construction, which is what makes it resistant to the length-extension attack that breaks naive hash-then-concatenate schemes.
- SHA-256 is the sensible default. HMAC-SHA1 remains cryptographically sound as a MAC despite SHA-1 being broken for collisions, but new systems should not choose it.
- Compare signatures with a constant-time comparison in production code. An ordinary string equality check leaks information through how long it takes to fail.
- The key you paste here stays in your browser. Signing keys are exactly the kind of secret that should never be pasted into a server-side tool.
Is it private and secure?
Your privacy is built in. HMAC Generator runs completely on your device, so whatever you enter stays in your browser and is never transmitted, logged or stored on any server.
Network activity: none. Nothing is sent and nothing is fetched. This tool makes no network request at all once the page has loaded — which is why it keeps working if your connection drops.
You do not have to take that on trust — our privacy proof page publishes the Content-Security-Policy that enforces it, lists every third party it permits, and shows how to verify the whole claim yourself.
Learn more
Is It Safe to Paste Production Data Into Online Tools? — JWTs, API responses and env files get pasted into online formatters every day. Here's what actually happens to that data and how to check before you paste.
Related tools
See all free developer tools or browse the full tool catalogue.