---
title: "HMAC Generator"
description: "Generate HMAC signatures with SHA-1, SHA-256, SHA-384 or SHA-512 to verify webhooks and sign API requests. Runs in your browser; nothing is uploaded."
url: https://findutils.com/security/hmac-generator/
category: security
---

# HMAC Generator

Generate HMAC signatures with SHA-1, SHA-256, SHA-384 or SHA-512 to verify webhooks and sign API requests. Runs in your browser; nothing is uploaded.

**Use this tool:** [HMAC Generator](https://findutils.com/security/hmac-generator/)

## Programmatic access

- REST id `hmac-generate`: POST https://api.findutils.com/api/tools/hmac-generate/execute (reference: https://findutils.com/api/hmac-generate/)
- MCP tool `hmac_generate` on https://mcp.findutils.com (reference: https://findutils.com/mcp/hmac-generate/)

## Why Use HMAC?

HMAC is essential for secure API authentication, webhook verification, and data integrity checks. Unlike simple hashes, HMAC uses a secret key that only the sender and receiver know, preventing tampering and ensuring the message came from a trusted source.

## Tips for Working with HMAC

- Always use HMAC-SHA256 or SHA-512 for new projects. SHA-1 is only recommended for legacy system compatibility.
- Keep your secret key truly secret. Never embed it in client-side code, URLs, or public repositories.
- Use a cryptographically random key of at least 32 bytes. Short or predictable keys weaken HMAC security significantly.
- When comparing HMAC signatures, use a constant-time comparison function to prevent timing attacks that could leak information about the expected value.
- For webhook verification, always compute the HMAC over the raw request body bytes, not a parsed or re-serialized version, to avoid subtle encoding differences.

## Frequently Asked Questions

### What's the difference between HMAC and a regular hash?

A regular hash (like SHA-256) only verifies data integrity. HMAC combines the hash with a secret key, providing both integrity AND authentication - proving the message came from someone who knows the secret.

### Which HMAC algorithm should I use?

HMAC-SHA256 is the most common choice, offering a good balance of security and performance. SHA-512 provides more security for highly sensitive data. Avoid SHA-1 for new implementations.

### How is HMAC used in APIs?

APIs often use HMAC to sign requests. The client creates an HMAC of the request data using a shared secret, and the server verifies it. This ensures the request wasn't tampered with and came from an authorized source.

### Is my secret key sent to your servers?

No. All HMAC calculations happen locally in your browser using the Web Crypto API. Your secret key and data never leave your device.

### Can HMAC be reversed to get the original message?

No. HMAC is a one-way function like hashing. You cannot reverse it to get the original message or secret key. It's only used for verification, not encryption.

### What is the recommended HMAC key length?

Use a key that is at least as long as the hash output. For HMAC-SHA256, that means a minimum of 32 bytes (256 bits). Keys shorter than the hash output reduce security, while keys longer than the block size are first hashed down internally.

### How do I verify a Stripe webhook signature using HMAC?

Stripe sends an HMAC-SHA256 signature in the Stripe-Signature header. Compute the HMAC of the raw request body using your webhook signing secret, then compare the result to the signature in the header using a constant-time comparison.

### Is HMAC-SHA256 the same as HS256 in JWT?

Yes. HS256 is the JWT specification name for HMAC-SHA256. When a JWT uses the HS256 algorithm, it signs the token header and payload with HMAC-SHA256 using a shared secret key.

### Can I use HMAC for password hashing?

HMAC alone is not suitable for password hashing. Passwords should be hashed with a dedicated password hashing function like bcrypt, scrypt, or Argon2 that includes salting and key stretching to resist brute-force attacks.

### What is the difference between HMAC-SHA256 and HMAC-SHA512?

HMAC-SHA512 produces a longer 512-bit output compared to SHA-256's 256-bit output, providing a larger security margin. SHA-512 can also be faster than SHA-256 on 64-bit processors. For most applications, both are considered equally secure.

## Related Tools

- [MD5 Hash Generator](https://findutils.com/security/md5-hash-generator/)
- [Hash Comparison Tool](https://findutils.com/security/hash-comparison-tool/)
- [Random Key Generator](https://findutils.com/security/random-key-generator/)
- [JWT Generator](https://findutils.com/security/jwt-generator/)
- [JWT Decoder](https://findutils.com/developers/jwt-decoder/)
- [Text Encryption](https://findutils.com/security/text-encryption/)
- [File Hash Calculator](https://findutils.com/security/file-hash-calculator/)
