About HMAC Generator
An HMAC generator shows the signature a server expects, which is the quickest way to debug a rejected API request or webhook. Payment gateways, cloud APIs and services such as GitHub sign requests with HMAC, most often HMAC-SHA256. Paste the exact string to sign, enter the secret key, and compare the result with the one your code or the provider produced.
The key can be entered as text, hex or Base64, since providers hand out secrets in all three forms. Pick SHA-256, SHA-1, SHA-384, SHA-512 or MD5 as the hash function, and get the signature as hex or Base64 to match what the other side sends. When the values don't match, the string to sign is almost always the cause: parameter order, a trailing line break or a different character encoding. Everything runs in your browser, so the secret never leaves your device.
How to use HMAC Generator
- 1Enter the message
Paste the exact string to sign, with nothing extra at the end.
- 2Enter the secret key
Type or paste the key and set whether it's text, hex or Base64.
- 3Pick the hash
SHA-256 is the usual choice. SHA-1, SHA-384, SHA-512 and MD5 are there too.
- 4Copy the signature
Choose hex or Base64 output and compare it with the expected value.
Why use Cubfile for this
- Five hash functions
HMAC with SHA-256, SHA-1, SHA-384, SHA-512 or MD5.
- Keys in any common form
Enter the secret as plain text, hex or Base64.
- Hex or Base64 output
Match the format your API or webhook uses.
- Secret stays local
Computed in your browser, with nothing sent or stored.