How to use HMAC Generator
Get the best out of HMAC Generator: every option explained, a worked example, and what to check when the output is not what you expected.
Updated July 31, 2026
What it does
Generate secure HMAC signatures using SHA-256 and a secret key. It runs entirely in your browser — your input never leaves your device.
Options
Every setting this tool exposes, straight from the code that validates it.
| Option | Type | Default | What it does |
|---|---|---|---|
text | text | — | Message to authenticate. Required. |
secretKey | text | — | HMAC secret key. Accepts at least 1 characters. Required. |
algorithm | one of: SHA256, SHA1, SHA512, MD5 | SHA256 | Which algorithm to use. Different algorithms produce different, incompatible output. Defaults to SHA256. |
Worked example
Run these settings on the tool page:
text:hellosecretKey:examplealgorithm:SHA256
You get:
be31ce2c9ec929d1a212202123a293cab1fc604d825c167132f557f7606c32e7
Getting the result you want
Most of the control here is in the options above. If the output is not what you expected, the setting to check first is algorithm — those change the shape of the output rather than the input it accepts.
Troubleshooting
- Nothing happens / the output stays empty.
text,secretKeyare required — the tool waits until you provide them. - A value is rejected.
secretKeyaccepts at least 1 characters. Anything outside that is refused rather than silently clamped. - It is slow on very large input. Everything runs in your browser, so speed depends on your device. Very large inputs are best split up, or run through the API where the work happens on our servers.
Automating it
The same logic is available as a REST endpoint, so you can run it from a script, a CI job or your own app.
Bashcurl "https://api.toolsxpo.com/v1/hmac-generator" \ -H "Authorization: Bearer $TOOLSXPO_KEY"
It costs 1 credit per successful call. See the full endpoint reference, or try it in the playground.
Related tools
Tools covered here
Related
How to use AES Encryption
Get the best out of AES Encryption: every option explained, a worked example, and what to check when the output is not what you expected.
How to use API Mock Payload Builder
Get the best out of API Mock Payload Builder: every option explained, a worked example, and what to check when the output is not what you expected.
How to use ASCII Chart
Get the best out of ASCII Chart: every option explained, a worked example, and what to check when the output is not what you expected.
How to use ASCII to Text
Get the best out of ASCII to Text: every option explained, a worked example, and what to check when the output is not what you expected.