Neatbo.

HMAC-SHA256 generator

Calculate a SHA-256 HMAC and compare it with a supplied signature in Hex, Base64 or Base64URL.

Browser-local processingInputUTF-8 message + keyOutputHex / Base64 / Base64URL
  1. 1Add input
  2. 2Adjust settings
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run
0 characters · 0 bytes

The key is UTF-8 text. It is hidden on screen and cleared when you leave this tool.

Signature options

Choose the signature encoding your integration uses; the underlying HMAC-SHA256 bytes are the same.

Output encoding

Hex accepts an optional sha256= prefix. Base64 uses padding; Base64URL has none. This local comparison does not verify a sender's identity.

Preparing the tool…

Before you start

Calculate an HMAC-SHA256 from exact UTF-8 message text and a UTF-8 key. Choose Hex, Base64 or Base64URL, then optionally compare a known signature. The key is hidden while you work and cleared when you leave this tool.

How to use this tool

  1. Enter the exact message text and a UTF-8 key. Use the show control only when you need to check the key.
  2. Choose Hex, Base64 or Base64URL to match the format expected by your integration.
  3. Optionally paste a known signature in that format; calculate and check the match result.
  4. Copy or download the selected signature.

Supported inputs and limits

The message and key are UTF-8 text. Even one different space or line ending changes the result; pasted text cannot guarantee the original bytes of a live HTTP request. Empty messages are valid, but a key is required.

Hex comparison accepts an optional sha256= prefix. Base64 signatures are padded and Base64URL signatures are unpadded. A local match is a debugging aid, not server-side sender verification or a full JWT/Webhook validator.

Processing stays in your browser. The key is not included in results or retained in the site workspace after leaving this tool. Message text is limited to 1 MiB; the key and comparison signature share the tool parameter limit.

Worked example

Example input

The quick brown fox jumps over the lazy dog
Example options
{"format":"hex"}

Example output

f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8

When something does not work

Enter a key and the exact message. If comparing signatures, choose the matching encoding and use a complete signature in that format.

Frequently asked questions

Can this verify a live webhook sender?

No. This page compares text-based HMAC results for debugging. Your server must validate the signature using the original request bytes and the provider’s complete signing rules.

Is my key saved?

The key stays in this browser tab only while you use this tool. It is hidden by default, never included in the result or download, and cleared when you leave the tool.

Why does my signature differ?

Check the exact message bytes, key encoding and output format. A space, newline, re-serialized JSON body, or a Hex/Base64/Base64URL mismatch changes what you compare.

Documentation & further reading

Related tools