Hash Generator (MD5, SHA-256)→Specialized Version
#️⃣

HMAC Generator

Generate HMAC signatures

HMAC-SHA-256hex encoded
—

Compare signatures with a constant-time function on the server (crypto.timingSafeEqual in Node) — a plain === leaks the answer through timing.

HMAC Generator

Generate HMAC (Hash-based Message Authentication Code) signatures for API authentication and message integrity verification. HMAC combines a cryptographic hash with a secret key to create unforgeable signatures.

Understanding HMAC

PropertyDescription
PurposeMessage authentication
ComponentsMessage + Secret key + Hash
OutputFixed-size signature
SecurityProves message origin & integrity

HMAC vs Plain Hashing

FeaturePlain HashHMAC
Uses secret keyNoYes
Verifies senderNoYes
Prevents tamperingDetectsDetects + authenticates
API securityInsufficientRecommended

HMAC Implementation

``javascript // Node.js const crypto = require('crypto');

function generateHmac(message, secret, algorithm = 'sha256') { return crypto .createHmac(algorithm, secret) .update(message) .digest('hex'); }

// Example const signature = generateHmac('Hello World', 'my-secret-key'); // "a1b2c3d4e5f6..."

// Verify HMAC function verifyHmac(message, secret, signature) { const expected = generateHmac(message, secret); return crypto.timingSafeEqual( Buffer.from(signature), Buffer.from(expected) ); } `

Web Crypto API (Browser)

`javascript async function generateHmacBrowser(message, secret) { const encoder = new TextEncoder(); const key = await crypto.subtle.importKey( 'raw', encoder.encode(secret), { name: 'HMAC', hash: 'SHA-256' }, false, ['sign'] );

const signature = await crypto.subtle.sign( 'HMAC', key, encoder.encode(message) );

return Array.from(new Uint8Array(signature)) .map(b => b.toString(16).padStart(2, '0')) .join(''); } `

API Request Signing

`javascript // Sign an API request function signRequest(method, path, body, timestamp, secret) { const message = ${method}\n${path}\n${timestamp}\n${body}; return generateHmac(message, secret); }

// Example const signature = signRequest( 'POST', '/api/orders', JSON.stringify({ item: 'book', qty: 1 }), Date.now().toString(), 'api-secret-key' ); `

Common HMAC Algorithms

AlgorithmSecurityUse Case
HMAC-MD5WeakLegacy only
HMAC-SHA1AcceptableOAuth 1.0
HMAC-SHA256StrongAWS, Stripe, most APIs
HMAC-SHA512Very strongHigh-security needs

The Avalanche Effect

A one-character change produces a completely different digest — not a similar one. That property is what makes a hash useful as a fingerprint:

InputMD5CRC32
hello5d41402abc4b2a76b9719d911017c5923610a686
hello.d94c10e437d18531e122ed0b45badd2a0a39d4f1
Hello8b1a9953c4611296a827abf8c47804d7f7d18982
hello and Hello differ by one bit of one byte, and share no part of their output. RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe` — same story.

Digest Length and Collision Resistance

AlgorithmOutputBirthday boundStatus
CRC3232 bits~77,000 valuesChecksum only
MD5128 bits2⁶⁴ in theoryBroken — collisions in seconds
SHA-1160 bits2⁸⁰ in theoryBroken — SHAttered, 2017
RIPEMD-160160 bits2⁸⁰No practical attack
SHA-256256 bits2¹²⁸Current standard
SHA-512512 bits2²⁵⁶Standard, faster on 64-bit
The birthday bound is where a 50% chance of *some* collision appears among random inputs. MD5 and SHA-1 fall far short of theirs because both have practical collision attacks — you can construct two different files with the same digest, which is precisely what a signature must prevent.

Never Hash a Password With These

A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.

Frequently Asked Questions

What is HMAC used for?

HMAC is used for message authentication—proving that a message came from someone with the secret key and wasn't modified in transit. Common uses include API request signing (AWS, Stripe), webhook verification, session tokens, and any scenario where you need to verify both integrity and authenticity of data.

Why use HMAC instead of just hashing?

Plain hashes can be computed by anyone with the data. HMAC requires both the data AND the secret key, proving the sender knows the secret. This prevents attackers from forging signatures or modifying messages. HMAC also protects against length extension attacks that affect plain SHA hashes.

Which HMAC algorithm should I use?

Use HMAC-SHA256 for most applications—it's secure, widely supported, and the standard for most APIs (AWS, Stripe, GitHub). Use HMAC-SHA512 for extra security margin. HMAC-SHA1 is acceptable for OAuth 1.0 compatibility. Avoid HMAC-MD5 unless required for legacy compatibility.

Related Tools

Explore other tools you might find useful:

More Hash Generator (MD5, SHA-256) tools

You might also need