HMAC Generator
Create an HMAC signature from a message and secret key with Web Crypto and display it as hexadecimal.
How to use
- Enter message, secret key, and SHA algorithm, then run.
Capabilities and scope
The dedicated runner rejects an empty secret and uses the selected SHA hash as the HMAC key algorithm parameter.
How it works
The UTF-8 secret is imported with crypto.subtle.importKey for HMAC and the UTF-8 message is signed with crypto.subtle.sign.
Example
The same secret, message, and algorithm produce the same HMAC hex.
Useful for
- Compare webhook-signature tests or HMAC implementations locally
Before you use it
- Security is lost if the secret is exposed, and protocol-specific canonicalization or header formatting is not applied automatically.
Standards and references
Frequently asked questions
Will this always equal my server's webhook signature?
Only if the exact message bytes, secret, algorithm, and protocol-specific preprocessing are the same.