HMAC generator

Loading…

All tools › Keyed digests

HMAC generator

A signature over a message with a key, and a check of one you were given.

It runs entirely in this browser tab: the passwords, keys and messages you type are never uploaded, and the tool makes no network request while it works. Open your browser's network panel and try it — nothing leaves the page.

Settings

The key
The shared secret both sides hold. It never leaves this page.
The key is written in
A key that is really bytes arrives as hex or Base64, and reading it as text gives a different signature. Choices: Text, Hexadecimal, Base64.
Digest
SHA-1 is what every authenticator does, whatever the standard allows; the other two are correct and will not scan. Choices: SHA-256, SHA-384, SHA-512, SHA-1, MD5.
Written as
Choices: Hexadecimal, Base64.
Check against
A signature you were given. It is compared without stopping at the first difference, which is what keeps the timing from saying how much was right.

How to use it

  1. Paste your text into the box above, or open a file.
  2. Adjust the settings beside it until the result is what you wanted.
  3. Copy the result, or save it as a file. The result updates as you type.

Questions

Is this audited cryptography?
No, and every result that rests on a cipher says so. Each algorithm here matches the vectors its own standard publishes, which proves it computes the right function; it does not prove there is no timing leak, and no test in this workspace could. For anything that matters, use an implementation somebody has reviewed.
Is what I type uploaded anywhere?
No. The whole tool is carried as WebAssembly and runs on your own device. No password, key, message or certificate is sent anywhere, and nothing is stored beyond the settings you chose.
Why does a tool ask me for a word list?
Because shipping one would be worse than not. A usable list of common passwords is bigger than everything else on this page put together, and a small one is actively harmful — it calls a leaked password uncommon. Paste your own and it is used, and it does not leave the page either.
Does a check here mean my key is safe?
It means the shape matched or the arithmetic came out. A scanner finds what it was written to find; a certificate that parses is well formed, not trusted; a password that is not in your list is a password nobody has leaked yet. Each tool says which of those it just told you.

Other tools for keyed digests

Basic auth header
A name and a password as a header, and back — and why that is not hiding it.

Htpasswd line
A line of a web server's password file, with the scheme it cannot write named.

All eighteen tools