Empty message is fine: HMAC of an empty string is still a valid signature.
Computed locally with your browser's WebCrypto API. Nothing is uploaded or stored.
Frequently asked questions
What is HMAC used for?
HMAC (Hash-based Message Authentication Code) proves a message is authentic and has not been tampered with. APIs and webhooks (for example Stripe or GitHub) use it to verify that a request really came from someone holding the secret key.
Is my secret key sent to a server?
No. This tool uses your browser’s built-in WebCrypto API, so the key and the message never leave your device. There is no server involved at all, which makes it safe to use with real secrets.
Which algorithm should I pick: SHA-256, SHA-512 or SHA-1?
Use HMAC-SHA256 for almost everything; it is the modern default. HMAC-SHA512 is stronger but produces longer signatures. HMAC-SHA1 is legacy only: keep it for verifying old systems, never for anything new.
Preview
Related free tools
Free Base64 Encoder Decoder
Free Base64 encoder and decoder. Encode text to Base64 or decode Base64 back to text, righ
Free CSS Minifier Online
Free CSS minifier. Remove comments and whitespace from CSS to shrink file size and speed u
Free SHA-256 Hash Generator
Free SHA-256 hash generator. Hash text with SHA-256, SHA-384 or SHA-512 securely in your b