HMAC Calculator

Sign a message with HMAC using SHA-256, SHA-384 or SHA-512, and verify a signature another system published.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Sign message controls

The exact bytes are signed, so a trailing space or a different line ending changes the signature.

The key stays in this page. It is never written into the result, the summary or an error message, and it is never sent anywhere.

Text suits a passphrase. Hexadecimal suits a key shown as bytes, such as 0b0b0b0b, and spaces or colons between the pairs are ignored.

The other side must use the same hash. SHA-256 is the usual choice.

Paste a signature another system published. It is checked with the browser verify function, and the result says whether the two agree.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use HMAC Calculator

  1. Type or paste the message to sign, exactly as the other side will send it.
  2. Enter the secret key and say whether it is text or hexadecimal bytes.
  3. Pick the hash the other system uses and the way you want the signature written.
  4. Press Sign message and copy the result, or paste a published signature to have it verified.

Example: HMAC Calculator

Reproduce RFC 4231 Test Case 1 with its public sample key.

You add
Message: Hi There. Hexadecimal key: 0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b. Hash: SHA-256. Signature encoding: Hexadecimal. Verification signature: empty.
You get
The page reports an HMAC-SHA-256 signature of b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7, a 32 byte signature, and a table naming the hash, the key source and the message length.

Options

How the key is written
Text is read as UTF-8 bytes, which suits a passphrase. Hexadecimal suits a key published as bytes, and spaces, colons or dashes between the pairs are ignored.
Signature written as
The same signature bytes can be written as hexadecimal or as Base64. Pick whichever form the other system publishes.
Signature to verify
Paste a signature to have it checked with the browser verify function rather than by comparing two strings. The result says plainly whether the key and the message agree with it.

Supported inputs and limits

SHA-256, SHA-384 and SHA-512 only, all through the browser Web Crypto interface, which needs a secure page. A message is capped at 5,000,000 characters and a key at 4,096 bytes. The secret key has no default, is never written into the result, the summary or an error message, and it is not sent anywhere; the message is not sent either. Verification accepts a hexadecimal or Base64 signature. This page computes and compares signatures, and it does not store, manage or rotate keys.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

What verification actually proves

A matching signature shows that whoever produced it held the same key and signed the same bytes. It does not show who they were, and it says nothing about the message being correct, so keep the key agreement and the message meaning in a separate conversation.

Questions about HMAC Calculator

Is HMAC the same as a hash?

No. A plain hash of a message can be computed by anyone. An HMAC mixes the message with a secret key, so only a party that holds the key can produce the same signature.

Which hash should I choose?

Use the hash the other side already uses, because the two must match for a signature to agree. SHA-256 is the common default, and SHA-384 or SHA-512 are longer variants of the same family.

Why does a signature check fail when the key looks right?

A single missing space, a different line ending or the wrong key mode changes the signature. Text and hexadecimal keys are read as different bytes even when they look similar.

Where does my key go?

It stays in the page as you type and is used by the browser crypto call. The field is never filled from a default, and the key is not echoed back in the signature, the table or any error.

Project manager: Tony Hines · Content updated 1 October 2026 · Report a problem