# HMAC Generator

> Compute a Hash-based Message Authentication Code (HMAC) for any message and shared secret. Supports SHA-256, SHA-512, SHA-1, and MD5. All computation runs in your browser.

URL: https://uttir.com/hmac-generator
Categories: security-tools, developer-tools
Privacy: Computation runs entirely in your browser. Your message and secret never leave this device.

## About

HMAC (Hash-based Message Authentication Code, RFC 2104) is the standard way to verify both the integrity and authenticity of a message. Given a message and a shared secret, it produces a fixed-size tag that only the holder of the same secret can recompute.

This tool uses the RFC 2104 algorithm directly (no library magic) and outputs the MAC in hex. All computation runs in your browser, so even sensitive secrets never leave the device.

## How to use

1. **Pick an algorithm** — SHA-256 is the modern default. SHA-1 / MD5 are kept for compatibility with legacy systems; do not use them for new work.
2. **Enter the secret and message** — Secrets can be plain text or a hex string prefixed with "hex:". Messages are plain UTF-8 text.
3. **Copy the hex MAC** — Use the hex output directly in HMAC headers (e.g. X-Hub-Signature-256) or as a binary comparison key.

## FAQ

### Is my secret sent anywhere?

No. The HMAC is computed in your browser using a pure-JS implementation of RFC 2104. Nothing is uploaded.

### When should I use HMAC vs a plain hash?

Use a plain hash when anyone with the message can verify integrity. Use HMAC when only parties with the shared secret should be able to produce a valid tag — typical for API request signing and webhook verification.

### HMAC-SHA-256 vs SHA-256?

Plain SHA-256 only proves the message has not changed. HMAC-SHA-256 also proves the message was produced by someone with the secret. Use HMAC for any signed channel.

## Related tools

- [Hash Generator](https://uttir.com/hash-generator) — Generate MD5, SHA-1, SHA-256, and SHA-512 hashes of any text instantly.
- [JWT Sign (HS256 / RS256)](https://uttir.com/jwt-sign) — Sign a JSON Web Token with HS256 (HMAC shared secret) or RS256 (RSA private key). Output is a standard compact JWT (header.payload.signature).
- [Signature Maker](https://uttir.com/signature) — Draw a handwritten signature in your browser with mouse, trackpad, or touch. Pick a pen color, set the stroke width, and download the result as a transparent PNG. Free, no upload.

---

For the full HTML page with the live tool, visit https://uttir.com/hmac-generator.
This file is the markdown rendering at https://uttir.com/hmac-generator.md. See https://uttir.com/llms.txt for a site-wide summary.
