HMAC Generator & Verifier

Computes an HMAC (SHA-256, SHA-384, or SHA-512) of a text message or local file using exclusively the browser's crypto.subtle — never a manual implementation or a plain hash presented as HMAC. Accepts the secret in text, hexadecimal, Base64, or Base64URL, shows the result in hex/Base64/Base64URL, and verifies an existing signature with a resistant comparison. The secret is never shown by default, never included in downloaded reports, and never logged.

Processed on your device, no AIhasta 5.000.000 de caracteres o 100 MB de archivo

The message, secret, and result stay on your device.

or use a local file

The data is processed on your device and is never sent to the server.

Use cases

How to use this tool

  1. Enter the message or upload a file
  2. Enter the secret and choose the algorithm
  3. Generate or verify the HMAC

Frequently asked questions

Is a plain hash the same as an HMAC?
No. A plain hash (like SHA-256 of a message) doesn't use any secret and anyone can recompute it; an HMAC combines the message with a shared secret using a specific cryptographic construction, computed here with crypto.subtle.
Is the secret saved or sent anywhere?
No. The secret stays on your device, is never sent to a server, isn't included in downloaded reports, and isn't logged in analytics.

Related tools

← Back to home