HMAC Generator
Compute an HMAC with SHA-1, SHA-256, SHA-384 or SHA-512 in hex or base64, and reproduce GitHub, Stripe and Slack webhook signature headers.
HMAC Generator
Webhook signature helper
Reproduce the exact signature header a provider sends so you can verify or replay webhooks.
HMAC-SHA256 of the raw request body, hex, prefixed with sha256=.
Everything runs in your browser with the Web Crypto API. Your message and secret never leave this page.
Updated . Provided as is. Check the output before you rely on it in production.
How to use HMAC Generator
- 1
Enter your message
Paste the payload or raw request body you want to authenticate into the message box.
- 2
Add the secret key
Type the shared secret both sides agree on. It is combined with the message to produce the signature.
- 3
Pick algorithm and encoding
Choose SHA-256 or another hash, then hex or base64 to match what your server expects.
- 4
Use the webhook helper
Select GitHub, Stripe, or Slack to get the exact signed header string, including timestamp handling where required.
- 5
Copy the result
Copy the signature or the full header and compare it against the incoming request to confirm authenticity.
Questions and answers
What is an HMAC?
How do I verify a GitHub or Stripe webhook signature?
Which hash algorithm should I use?
Is my secret or message sent anywhere?
What is the difference between hex and base64 output?
For AI agents: how to call this tool
Machine-readable contract, endpoints and examples. Humans can ignore this section.
Best Path For Builders
Browser workflow
Runs instantly in the browser with private local processing and copy/export-ready output.
Browser Workflow
This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.
/hmac-generator/
For automation planning, fetch the canonical contract at /api/tool/hmac-generator.json.