What Is HMAC, and What Is It Used For?
HMAC (Hash-based Message Authentication Code) is a mechanism used to verify both a message's integrity and its sender. Unlike a plain hash function, HMAC also takes a secret key alongside the message and combines the two using a specific double-hashing scheme defined in RFC 2104 (key+inner padding+message is hashed first, then key+outer padding+that result is hashed again). This means only parties who know the same secret key can produce or verify a valid HMAC.
Critical distinction: HMAC is NOT the same as simply computing hash(key + message). That naive approach is vulnerable to what's called a "length-extension attack" — an attacker can append extra data on top of an existing hash and produce a new, seemingly valid hash without knowing the original message or key. HMAC's double-hash construction from RFC 2104 makes this attack mathematically impossible; that's why you should always use purpose-built HMAC for a signing mechanism, and never invent your own "key+message" concatenation.
The most common uses include API request signing (many cloud providers require an HMAC signature to prove a request wasn't tampered with), webhook verification (services like Stripe and GitHub attach an HMAC-SHA256 signature to every webhook request they send; the receiving server recomputes the same signature with its own secret key and compares it to confirm the request really came from that service), and JWT's (JSON Web Token) HS256 signing algorithm. As a developer testing a webhook integration or investigating why an API request's signature isn't validating, you can use this tool to manually reproduce and compare the expected HMAC value.
This tool runs entirely in your browser; the computation is done with the browser's built-in Web Crypto API (crypto.subtle) — neither your message nor your secret key is ever sent to a server at any stage. SHA-256 is recommended for most modern uses; as for output format, Hex offers readability, Base64 is more compact, and Base64URL can be used safely inside a URL or filename (e.g. JWT signatures).
Try This Next
Finished here? These might be your next step.
Frequently Asked Questions
hash(key+message)) is not a substitute for HMAC — that naive approach is vulnerable to a "length-extension attack".+// with -/_ and drops padding (=) so it can be used safely inside a URL or filename — JWT signatures use this form.Last updated: