ToolCabana
Language preview: no interface translation is available for this language yet. Showing English. Use English

HMAC generator

Sign text with an HMAC key that stays local.

Favorites are saved in this browser. Find them in My favorites.

HMAC generator

Your input stays in this browser unless stated otherwise
Clear your input, files and result, and restore the default settings.
Load sample text to explore what this tool can do. This replaces your current input.
0 charactersClear the source text.

How to use HMAC generator

HMAC generator signs a message with a secret key and returns the HMAC using SHA-256, SHA-384 or SHA-512. Both the message and the secret are read as exact UTF-8 bytes. The result can be lowercase hex, uppercase hex or Base64, which helps when checking webhook or API signatures.

  1. Paste the source into the input editor, or load the built-in example.
  2. Adjust the basic settings, then open Advanced mode for export and fine-tuning options. Custom settings stay active when the panel is closed.
  3. Run hmac generator, review the output, then use the available copy or download controls.

What this tool supports

Sign text with an HMAC key that stays local.

Secret key (stays in your browser)
Set this value for your task.
Algorithm
SHA-256 · SHA-384 · SHA-512
Digest format
hex · HEX · base64

Limits and processing

Text operations generally accept up to 2,000,000 characters. Individual parsers, generators and formulas apply additional limits shown by their controls.

Example source
Hello ToolCabana

Frequently asked questions

How do I generate an HMAC SHA-256 signature?

Paste the message, enter the secret key and keep the algorithm set to SHA-256, then run the tool. The output is the keyed HMAC of the message, not a plain hash.

Is my HMAC secret key encoded as hex or text?

The secret is used as the exact UTF-8 bytes of what you type. A hex or Base64 key string is not decoded first, so enter the key in the form your system uses.

Can I get the HMAC output in Base64?

Yes. Open Advanced mode and set Digest format to base64. Lowercase hex is the default, and uppercase HEX is also available.

Where is my input processed?

This operation processes its source in your browser. Copy and download are explicit actions; source input is not saved in an account or history.

What are the input limits?

Text operations generally accept up to 2,000,000 characters. Individual parsers, generators and formulas apply additional limits shown by their controls.