Free Online HMAC Generator for SHA-256, SHA-1, SHA-384 and SHA-512
Work out an HMAC over any text with SHA-1, SHA-256, SHA-384 or SHA-512. The key can be read as text, as hex or as base64, which is the usual reason a webhook signature does not match, and the result is given as hex and base64 together. Paste the signature you were sent and the page says whether it agrees.
Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.
When a Webhook Signature Will Not Match
Four causes, and the first two are the common ones.
Almost every failed webhook check comes down to one of four things, and none of them is the HMAC arithmetic. Working through them in order is quicker than reading the provider docs again.
How to Work Out an HMAC
A few steps, and nothing is uploaded.
What to Know About HMAC
Including the three reasons a signature usually fails to match.
Key Features & Capabilities
What this tool does, and what it deliberately does not.
About HMAC
An HMAC answers a narrow question: did this message come from someone holding the shared key, and has it been changed. It is the primitive behind webhook signatures, signed URLs, API request signing and session cookies, and it is built from an ordinary hash used twice with two keys derived from yours. That construction is what makes it safe where a plain hash of the secret and the message joined together is not.
This page exists mostly for debugging, because an HMAC that does not match is a miserable thing to chase. The arithmetic is never the problem: it is in the browser own cryptography here and in a vetted library at the other end. What differs is the input. The key is often hex or base64 and gets read as text, the message is often a re-serialised copy of the body rather than the raw bytes, and the two sides often disagree about hex versus base64. All three are visible on this page at once, which usually makes the answer obvious within a minute.
What the page deliberately does not do is pretend to validate anything. A matching HMAC tells you the sender had the key, and nothing about whether the request is fresh, whether it has already been processed, or whether the key has since been rotated. Those are decisions for the system receiving the request, and a tool that implied otherwise would be teaching the wrong lesson.
Frequently Asked Questions
Keys, output forms, and webhook signatures.
Every Other Security Tool
10 more tools in this set. All free, all in your browser.