For developers and security testers checking webhook or API request signatures. You get the hex HMAC of a message under your secret key, ready to compare with the signature a service sends.
Take an online exam and add a verified certificate to your public profile that anyone can check.
You enter
Key s3cr3t, message CareerByteCode, SHA-256
The tool shows
f9c7ad75c3fb9167abbf194165a0aaddb92c1432209d355848a0b0ee92fce23a
Compute the HMAC of the raw request body with the shared secret and the algorithm the provider documents, then compare it with the signature header. Any change in whitespace or encoding of the body gives a different result.
Anyone can recompute a plain hash, so it only detects accidental change. An HMAC mixes in a secret key, so only someone who holds the key can produce a valid tag, which shows the message came from them.
The usual causes are hashing a parsed or reformatted body instead of the raw bytes, a different algorithm, or comparing hex against Base64. This tool outputs lowercase hex.
Yes. It is free, needs no sign-up and runs entirely in your browser, so what you type is not uploaded. You only sign in if you want to email a result to yourself or save it to your CareerByteCode profile.