CareerByteCode

HMAC SHA-256 Generator

For developers and security testers checking webhook or API request signatures. You get the hex HMAC of a message under your secret key, ready to compare with the signature a service sends.

FreeRuns in your browserNothing uploadedNo sign-up neededAll 15 tools in the Security Toolbox
Keep this resultSign in to email it to yourself or save it to your profile. The tool itself never needs an account.

Exams

Prove it with a verified certificate

Take an online exam and add a verified certificate to your public profile that anyone can check.

See exams
How to use

How to use the HMAC Generator

  1. Enter the shared secret key.
  2. Pick SHA-256, SHA-384 or SHA-512 as the algorithm.
  3. Paste the exact message or request body into the Message box.
  4. Click Compute HMAC and compare the hex output with the expected signature.
Worked example

An example, step by step

You enter

Key s3cr3t, message CareerByteCode, SHA-256

The tool shows

f9c7ad75c3fb9167abbf194165a0aaddb92c1432209d355848a0b0ee92fce23a

FAQ

Questions about the HMAC Generator

How do I verify a webhook HMAC signature?

Compute the HMAC of the raw request body with the shared secret and the algorithm the provider documents, then compare it with the signature header. Any change in whitespace or encoding of the body gives a different result.

What is the difference between HMAC and a plain hash?

Anyone can recompute a plain hash, so it only detects accidental change. An HMAC mixes in a secret key, so only someone who holds the key can produce a valid tag, which shows the message came from them.

Why does my HMAC not match the one from the API?

The usual causes are hashing a parsed or reformatted body instead of the raw bytes, a different algorithm, or comparing hex against Base64. This tool outputs lowercase hex.

Is the HMAC Generator free and private?

Yes. It is free, needs no sign-up and runs entirely in your browser, so what you type is not uploaded. You only sign in if you want to email a result to yourself or save it to your CareerByteCode profile.

Copied