HMAC-SHA256 Generator
Generate an HMAC-SHA256 signature from a message and secret key.
This tool runs entirely in your browser. Nothing you type is uploaded, logged or stored, which makes it safe for keys, tokens and other sensitive values.
What Is HMAC SHA256?
HMAC (Hash-based Message Authentication Code) is a technique for combining a cryptographic hash function with a secret key to produce a keyed hash. Unlike a plain hash, an HMAC proves both that the message has not been altered (integrity) and that it was produced by someone who knows the secret key (authenticity).
HMAC-SHA256 is HMAC built on top of the SHA-256 hash function. It takes a message and a secret key and produces a 256-bit authentication tag, shown as a 64-character hexadecimal string. It is one of the most common HMAC constructions and is widely used in API authentication, webhook signing, and request signing.
A key distinction: authentication is not encryption. HMAC does not hide the message — the message can still be read in plain text. What it provides is a signature that a holder of the secret key can verify, and that an attacker without the key cannot forge.
How to Use HMAC SHA256
- Enter the message you want to sign in the Message field.
- Enter your secret key in the Secret Key field. Keep this key confidential.
- The HMAC-SHA256 signature is generated instantly as a 64-character hex string.
- Copy the signature to your clipboard or download it as a text file.
- Use Sample Data to load a sample message and key for quick testing.
Features
- Live HMAC-SHA256 computation as you type — no submit button, no network calls.
- 256-bit output rendered as a 64-character hexadecimal string.
- Separate message and secret key inputs for clear signing workflows.
- Copy to clipboard and download as a .txt file.
- Sample Data button for quick verification.
- Fully client-side computation using a trusted JavaScript crypto library.
Common Use Cases
- Reproducing an API signature while debugging a webhook or signed request.
- Verifying that a webhook payload was genuinely sent by the expected service.
- Signing requests to APIs that require HMAC authentication headers.
- Testing HMAC-based authentication flows during development.
- Learning how keyed hashing differs from plain hashing.
How It Works
HMAC mixes the key into the hashing process in a specific way. It computes the hash of the message combined with an inner padded key, then hashes that result combined with an outer padded key. This construction prevents length-extension attacks that would otherwise affect plain hash functions when used as a naive keyed hash.
Because the key is mixed into every round of computation through the padding scheme, an attacker cannot produce a valid HMAC for a new message without knowing the secret key, even if they have seen many previous message/tag pairs.
This tool uses CryptoJS to compute HMAC-SHA256 entirely in your browser. Neither the message nor the secret key is transmitted anywhere.
Security and Privacy Considerations
Keep your secret key confidential. Anyone who obtains the key can forge valid signatures. Never commit keys to source control or expose them in client-side code in production.
Use a strong, random secret key with sufficient entropy. Short or predictable keys can be brute-forced.
Compare HMACs in constant time on the server side. A naive string comparison can leak information through timing differences and allow signature forgery.
Authentication is not encryption. HMAC-SHA256 does not hide the message content; it only proves integrity and authenticity. If confidentiality is required, combine HMAC with encryption.
Common implementation mistakes include using the wrong encoding for the key or message, forgetting to include the full body in the signed data, and not protecting against replay attacks with timestamps or nonces.
This tool runs locally, so your message and key never leave your device — but the operational key-management guidance above still applies to how you use the resulting signature.
When to Use HMAC SHA256
- Signing API requests that require an HMAC authentication header.
- Verifying that a webhook payload was genuinely sent by the expected service.
- Reproducing an HMAC signature while debugging a signed request.
- Any context where you need to prove both integrity and authenticity of a message.
When Not to Use HMAC SHA256
- Cases where you need confidentiality — HMAC does not hide the message; combine it with encryption if needed.
- Password storage — HMAC is an authentication construction, not a password hash.
- Any case where the secret key cannot be kept confidential, since anyone with the key can forge tags.
Practical Examples
- Webhook verification: a service signs the request body with HMAC-SHA256 using a shared secret and sends the tag in a header. Your server recomputes the tag over the raw body and compares it in constant time to confirm the request is authentic and unmodified.
- API request signing: include an HMAC-SHA256 of the canonical request (method, path, headers, body, timestamp) with your secret key so the server can authenticate the caller without transmitting the key.
Comparison
- HMAC-SHA256 vs SHA-256: SHA-256 is an unkeyed hash proving only integrity; HMAC-SHA256 adds a secret key to also prove authenticity. Use HMAC whenever the origin of the data must be verified.
- HMAC-SHA256 vs HMAC-SHA512: both use the same HMAC construction. HMAC-SHA256 produces a 64-character tag; HMAC-SHA512 produces a 128-character tag with a larger margin. HMAC-SHA256 is sufficient and more compact for most applications.
Frequently Asked Questions
- What is the difference between a hash and an HMAC?
- A plain hash proves only integrity — that the data has not changed. An HMAC adds a secret key, so it also proves authenticity — that the signature was produced by someone who knows the key.
- Does HMAC encrypt my message?
- No. HMAC provides integrity and authentication, not confidentiality. The message remains in plain text. If you need confidentiality, use encryption in addition to HMAC.
- How long is an HMAC-SHA256 signature?
- HMAC-SHA256 produces a 256-bit tag, shown as a 64-character hexadecimal string.
- What are common HMAC mistakes?
- Using weak or leaked keys, comparing signatures with a non-constant-time comparison, signing only part of the request body, and not protecting against replay attacks with timestamps or nonces.
- Is my secret key uploaded?
- No. HMAC-SHA256 is computed entirely in your browser. Neither the message nor the key is sent to a server.