Sign up free

Online HMAC Generator for API Signatures

Sign a message with a secret key and get the HMAC in hex or Base64.

About HMAC Generator

An HMAC generator shows the signature a server expects, which is the quickest way to debug a rejected API request or webhook. Payment gateways, cloud APIs and services such as GitHub sign requests with HMAC, most often HMAC-SHA256. Paste the exact string to sign, enter the secret key, and compare the result with the one your code or the provider produced.

The key can be entered as text, hex or Base64, since providers hand out secrets in all three forms. Pick SHA-256, SHA-1, SHA-384, SHA-512 or MD5 as the hash function, and get the signature as hex or Base64 to match what the other side sends. When the values don't match, the string to sign is almost always the cause: parameter order, a trailing line break or a different character encoding. Everything runs in your browser, so the secret never leaves your device.

How to use HMAC Generator

  1. 1
    Enter the message

    Paste the exact string to sign, with nothing extra at the end.

  2. 2
    Enter the secret key

    Type or paste the key and set whether it's text, hex or Base64.

  3. 3
    Pick the hash

    SHA-256 is the usual choice. SHA-1, SHA-384, SHA-512 and MD5 are there too.

  4. 4
    Copy the signature

    Choose hex or Base64 output and compare it with the expected value.

Why use Cubfile for this

  • Five hash functions

    HMAC with SHA-256, SHA-1, SHA-384, SHA-512 or MD5.

  • Keys in any common form

    Enter the secret as plain text, hex or Base64.

  • Hex or Base64 output

    Match the format your API or webhook uses.

  • Secret stays local

    Computed in your browser, with nothing sent or stored.

FAQ

HMAC Generator: questions and answers

What is an HMAC signature, and how does it work?
A signature made from a message and a secret key with a hash function. Only someone with the same key can produce the same value, so the receiver knows the message is genuine and unchanged.
Why doesn't my HMAC match the API's?
Check the string to sign character by character, because parameter order, spaces, line breaks and URL encoding all change the result. Then check the key format and whether hex or Base64 output is expected. Viewing both strings in the Text to Hex Converter makes hidden spaces and line breaks easy to spot.
Is HMAC-SHA256 the same as SHA-256?
No. SHA-256 hashes only the message, while HMAC-SHA256 mixes in the secret key in a defined way. Appending the key to the text and hashing that gives a different value. A plain SHA-256 of the text, without a key, comes from the Hash Generator.
How do I check a GitHub webhook signature?
Use the raw request body as the message and your webhook secret as a text key, with SHA-256 and hex output. The result should equal the part after sha256= in the X-Hub-Signature-256 header.
Is my secret key safe here?
Yes. The HMAC is calculated in your browser and nothing is uploaded or stored, so the key never reaches our servers.
Share HMAC Generator with a friendIt runs in any browser, and they can try it without signing up.

Related tools

HASH Hash GeneratorGet MD5, SHA-1, SHA-256, SHA-512 and SM3 hashes of text in one go.
TIME Unix Timestamp ConverterConvert Unix timestamps to dates and back, in your time zone and UTC.
U+UNI Unicode ConverterConvert text to and from \u escapes, &#; codes, U+ points and UTF-8 bytes.
AES AES Encrypt and DecryptEncrypt or decrypt text with AES in GCM, CBC or CTR mode.
&;HTML HTML Entity Encoder/DecoderEscape text into HTML entities, or turn entities back into text.
JWT JWT DecoderDecode a JSON Web Token’s header and payload and check its expiry and signature.
01BIN Number Base ConverterConvert numbers between binary, octal, decimal, hex and any base up to 36.
BASE Base32 and Base58 EncoderEncode and decode Base32, Base58, Base85 and Base16.