dev/generator

HMAC Generator - Free & Instant | Smocky

Nothing leaves your browser

Text, Hex, or Base64 — up to 65,536 characters. Excess input is reported, never truncated.

Text, Hex, or Base64 — up to 65,536 characters. Excess input is reported, never truncated.

Output format

Enter a Message and Secret key, then Generate to compute an HMAC tag.

What is HMAC?

HMAC (Hash-based Message Authentication Code) combines a message with a shared secret key to produce an authentication tag. A receiver with the same key can recompute the tag to check whether the message was changed.

Unlike a plain hash, HMAC requires a secret key. It does not encrypt the message or hide its contents. For API signing, both sides must use the same algorithm, key bytes, and exact message bytes—including whitespace and line endings.

A sender/receiver example

Sender: using the fictional shared key example-shared-secret-only, the sender computes an HMAC tag over the Message and sends the Message and the tag together — the key itself is never sent.

Receiver: holding the same fictional key, the receiver recomputes the tag over the Message it received and compares the two tags. A match means the Message arrived as sent by someone who holds the shared key; a mismatch means the Message changed, or the keys differ.

This Tool only generates tags from the bytes you supply here. It does not send or authenticate API requests, and replay protection and request canonicalization belong to the API's own protocol, not to this Tool.

Frequently asked questions

How is an HMAC tag different from a plain hash Digest?

A Digest — like the ones the Hash Generator produces — is unkeyed: anyone can compute it from the Message alone, so it detects accidental corruption but proves nothing about who produced it. An HMAC tag additionally requires a Secret key: only someone who holds that key can produce or verify the matching tag, which is what makes it useful for authenticating a Message rather than just checking it.

Does HMAC encrypt the Message, or is it the same as a digital signature?

Neither. HMAC never encrypts or hides the Message — this Tool's output is a fixed-size tag alongside the plain Message, not ciphertext. It is also not a public-key digital signature: HMAC uses one shared Secret key that both sides must already have, while a digital signature uses a private key to sign and a separate public key to verify, and can prove authorship to a third party. HMAC only lets someone who already holds the shared key check a tag.

Why does changing only the input encoding change the tag?

An HMAC tag is computed over exact bytes, not over the text you typed. Text, Hex, and Base64 are three ways to describe those bytes: the Hex key `6162` and the Base64 key `YWI=` both decode to the same two bytes and produce the same tag, but the four-character Text key `6162` decodes to four different bytes and produces a different tag. The same applies to a Message's trailing newline or trailing whitespace — changing it changes the bytes, and therefore the tag.

Can I generate a tag for an empty Message?

Yes. An empty Message — including an empty Hex or Base64 input that decodes to zero bytes — is valid and produces a well-defined tag. A Secret key that decodes to zero bytes is rejected instead, because an empty key defeats the purpose of keying the computation.

Can I use this Tool to sign and send an API request?

No. This Tool only computes a tag from the bytes you supply; it never constructs, sends, or authenticates an HTTP request. Replay protection (such as a timestamp or nonce) and request canonicalization (deciding exactly which bytes to sign) are the responsibility of the API's own protocol — get those exactly right before comparing tags.

Should I use HMAC-MD5 or HMAC-SHA-1?

Only for compatibility with a system that already requires them, such as some legacy webhook providers. Unlike an unkeyed MD5 or SHA-1 Digest, HMAC-MD5 and HMAC-SHA-1 have no known practical attack that recovers the Secret key or forges a tag without it, but HMAC-SHA-256 or a stronger Algorithm is the better default when you control both ends.

Send feedback

About Smocky

Send this feedback to Smocky via Cloudflare, a third-party service. Only the feedback you enter is included, along with your browser information. Your tool inputs and results are never attached. Please do not include passwords or other sensitive information. Privacy policy

Feedback is unavailable right now. Your draft is still here.