HMAC Calculator
Compute a keyed message authentication code (HMAC).
Compute HMAC with MD5, SHA-1, SHA-256, SHA-384, or SHA-512. Free, offline, runs in your browser. Read more Show less
What is HMAC?
HMAC (Hash-based Message Authentication Code) is a keyed hash used to verify both the integrity and authenticity of a message. It is defined in RFC 2104. Given a secret key and a message, HMAC produces a fixed-size tag. Anyone with the key can recompute the tag and verify the message was not tampered with.
Where is HMAC used?
HMAC is used in TLS, JWTs (HS256, HS384, HS512), AWS request signing, API authentication, and file integrity. Never send the key over an untrusted channel.
FAQ
Which algorithm should I use?
HMAC-SHA-256 is the recommended default. Use HMAC-SHA-512 for higher security margins. HMAC-MD5 and HMAC-SHA-1 are only for compatibility with legacy systems.
HMAC vs plain hash
A plain hash proves the data was not accidentally changed. HMAC also proves the data was produced by someone holding the secret key.