Where HMAC is used
- Webhook signatures (Stripe, GitHub, Shopify, Slack) — verify that a webhook really came from the provider.
- API request signing (AWS Signature, many payment gateways).
- Signed cookies and tokens (JWT HS256 is HMAC-SHA256).
How to verify a webhook
- Take the raw request body exactly as received.
- Compute HMAC-SHA256 with your webhook secret.
- Compare it with the signature header (hex or Base64) using a constant-time comparison.
This tool calculates HMACs with the browser's Web Crypto API, so your key stays on your device. For plain hashes without a key, use the MD5 & SHA Hash Generator.
Frequently asked questions
Hex or Base64?
They are the same signature in two encodings. Use the one your API or webhook provider expects.
Is HMAC encryption?
No. It proves authenticity and integrity; the message itself is not hidden.
Why does my HMAC not match?
The message must be byte-for-byte identical, including whitespace and line endings, and the key must be exact.

