How to use HMAC Calculator
- Type or paste the message to sign, exactly as the other side will send it.
- Enter the secret key and say whether it is text or hexadecimal bytes.
- Pick the hash the other system uses and the way you want the signature written.
- Press Sign message and copy the result, or paste a published signature to have it verified.
Example: HMAC Calculator
Reproduce RFC 4231 Test Case 1 with its public sample key.
Options
- How the key is written
- Text is read as UTF-8 bytes, which suits a passphrase. Hexadecimal suits a key published as bytes, and spaces, colons or dashes between the pairs are ignored.
- Signature written as
- The same signature bytes can be written as hexadecimal or as Base64. Pick whichever form the other system publishes.
- Signature to verify
- Paste a signature to have it checked with the browser verify function rather than by comparing two strings. The result says plainly whether the key and the message agree with it.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
What verification actually proves
A matching signature shows that whoever produced it held the same key and signed the same bytes. It does not show who they were, and it says nothing about the message being correct, so keep the key agreement and the message meaning in a separate conversation.
Questions about HMAC Calculator
Is HMAC the same as a hash?
No. A plain hash of a message can be computed by anyone. An HMAC mixes the message with a secret key, so only a party that holds the key can produce the same signature.
Which hash should I choose?
Use the hash the other side already uses, because the two must match for a signature to agree. SHA-256 is the common default, and SHA-384 or SHA-512 are longer variants of the same family.
Why does a signature check fail when the key looks right?
A single missing space, a different line ending or the wrong key mode changes the signature. Text and hexadecimal keys are read as different bytes even when they look similar.
Where does my key go?
It stays in the page as you type and is used by the browser crypto call. The field is never filled from a default, and the key is not echoed back in the signature, the table or any error.