That page doesn't exist. Search or drop a file below to find the tool you need.
What do you need to get done?
- Stays on this device
- No watermark
- Works offline
Drop a file here
or .
Open an app
Follow a recipe
Use one tool
HMAC-SHA256 hash generator
Calculate an HMAC-SHA256 of a message with your own secret key, online and free. The keyed hash appears next to the plain hashes of the same text, in 64 hex characters. Useful for checking webhook signatures and API requests. Nothing is uploaded.
How to calculate an HMAC-SHA256 online
- 1Type the message, or drop a text file
- 2Enter your secret key in the "HMAC key (optional)" box
- 3Copy the HMAC-SHA256 line from the list
- A 64-character HMAC-SHA256, in hex.
What you get
- Your key stays with you.Key and message are used in your browser and are never sent anywhere.
- Keyed and plain together.The HMAC lines come with the plain hashes of the same text.
- Hex output, lower or upper.Switch to capitals with "Uppercase" to match a service's format.
What you can do
- Enter a key and a message and get HMAC-SHA256 at once, updated as you type.
- See HMAC-SHA-1, HMAC-SHA-256, HMAC-SHA-384 and HMAC-SHA-512 of the same message in one list.
- Drop a text file to use its content as the message.
- Compare the result with the signature a webhook or API sends, such as a GitHub or Stripe style header.
- Use it to check HS256 style signatures, since HMAC-SHA256 is the most common choice for them.
Good to know
- HMAC lines only appear once the key box is filled. With an empty key you see plain hashes.
- Key and message are read as UTF-8 text. A binary or hex key is not decoded, so a hex key is used as its characters.
- The message must match byte for byte, including spaces and the final newline, or the HMAC will differ.
- HMAC-SHA256 output is 64 hex characters, or 32 bytes. Services that send it as Base64 need the value converted first.
Questions
What is HMAC-SHA256?
A hash of a message mixed with a secret key, using SHA256. Only someone with the key can produce the same value, so it proves the message is genuine and unchanged.
Is my secret key sent to a server?
No. The calculation runs in your browser, and neither the key nor the message leaves your device.
Why does my HMAC not match the service's?
Usually the message differs by a space, a line break or the encoding, or the service signs the raw request body. Check those first.
Is HMAC-SHA256 the same as SHA-256?
No. SHA-256 hashes only the text. HMAC-SHA256 also mixes in a secret key, so the result differs and cannot be forged without the key.