HMAC-SHA256 generator
Calculate a SHA-256 HMAC and compare it with a supplied signature in Hex, Base64 or Base64URL.
- 1Add input
- 2Adjust settings
- 3Get your result
Tool input and files are processed in this browser without being uploaded.
Before you start
Calculate an HMAC-SHA256 from exact UTF-8 message text and a UTF-8 key. Choose Hex, Base64 or Base64URL, then optionally compare a known signature. The key is hidden while you work and cleared when you leave this tool.
How to use this tool
- Enter the exact message text and a UTF-8 key. Use the show control only when you need to check the key.
- Choose Hex, Base64 or Base64URL to match the format expected by your integration.
- Optionally paste a known signature in that format; calculate and check the match result.
- Copy or download the selected signature.
Supported inputs and limits
The message and key are UTF-8 text. Even one different space or line ending changes the result; pasted text cannot guarantee the original bytes of a live HTTP request. Empty messages are valid, but a key is required.
Hex comparison accepts an optional sha256= prefix. Base64 signatures are padded and Base64URL signatures are unpadded. A local match is a debugging aid, not server-side sender verification or a full JWT/Webhook validator.
Processing stays in your browser. The key is not included in results or retained in the site workspace after leaving this tool. Message text is limited to 1 MiB; the key and comparison signature share the tool parameter limit.
Worked example
Example input
The quick brown fox jumps over the lazy dog
Example options
{"format":"hex"}Example output
f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8
When something does not work
Enter a key and the exact message. If comparing signatures, choose the matching encoding and use a complete signature in that format.
Frequently asked questions
Can this verify a live webhook sender?
No. This page compares text-based HMAC results for debugging. Your server must validate the signature using the original request bytes and the provider’s complete signing rules.
Is my key saved?
The key stays in this browser tab only while you use this tool. It is hidden by default, never included in the result or download, and cleared when you leave the tool.
Why does my signature differ?
Check the exact message bytes, key encoding and output format. A space, newline, re-serialized JSON body, or a Hex/Base64/Base64URL mismatch changes what you compare.
Documentation & further reading
Related tools
Base64 encode / decode
Encode or decode a snippet in a click.
URL encode / decode
Make those encoded characters readable again.
HTML entities
Convert between HTML entities and readable characters.
Unicode escape
Convert Unicode escapes into readable text and back.