🧰Locly

Generate HMAC Hashes

Generate HMAC-SHA1/SHA256/SHA512 digests in your browser

Keys and messages are processed locally in your browser with Web Crypto and never uploaded.

About This Tool

HMAC Generator creates keyed-hash message authentication codes using HMAC-SHA1, HMAC-SHA256, or HMAC-SHA512 via the Web Crypto API. Enter a message and secret to get hex and Base64 digests. Secrets never leave your device β€” everything is processed locally in your browser.

How to Use

  1. Enter the message to authenticate
  2. Enter your secret key
  3. Choose SHA-1, SHA-256, or SHA-512
  4. Click Generate HMAC
  5. Copy the hex digest (or use Base64)

Common Use Cases

  • API: Verify HMAC signatures during debugging
  • Webhooks: Reproduce provider signatures locally
  • Learning: Compare algorithms on the same payload
  • QA: Generate known digests for test fixtures
  • Privacy: Sign without posting secrets online

FAQ

Q1: Which algorithms are supported?

HMAC-SHA1, HMAC-SHA256, and HMAC-SHA512 via Web Crypto.

Q2: Does my secret leave the browser?

No. Signing is processed locally in your browser.

Q3: What outputs do I get?

Both hexadecimal and Base64 encodings of the same digest.

Q4: Why is empty input blocked?

Both message and secret are required to compute an HMAC.

Related Tools