Turning a key and a message into an HMAC signature
Use this when a request needs a signature attached, or when you want to check your own calculation against a signature a server produced. Enter a key and a message, pick HMAC-SHA256, SHA-384 or SHA-512, and the signature appears as both hex and Base64. The key can be typed as text, which is encoded to UTF-8 bytes, or written in hex so the raw bytes are passed through unchanged.
Everything runs on Web Crypto, built into the browser, and the key is never sent to a server. The implementation was checked against the test values published in RFC 4231: signing the message what do ya want for nothing? with the key Jefe under HMAC-SHA256 must start with 5bdcc146, and this page produces exactly that.
Only a holder of the secret key can produce a valid signature, which means the key itself ends up on screen and in your clipboard. On a shared machine, press Clear the key afterwards. This page generates signatures; it does not decide whether a received signature matches. Written as of October 2026.
Frequently asked questions
HMAC takes a byte array as its key. Choosing text encodes what you typed as UTF-8 bytes; choosing hex reads the digits as raw bytes. Reading the same key differently changes the signature.
The signed bytes are most likely different. Line endings, a trailing space or JSON whitespace all change the result, so paste the exact body you sent, byte for byte.
This page supports SHA-256, SHA-384 and SHA-512 only. Web Crypto does not provide MD5, and there is no reason to pick either for a new signature.