SECURITY
Hash & HMAC Generator
Hash text with SHA-1, SHA-256, SHA-384 or SHA-512, and sign it with HMAC, entirely in your browser.
Hash vs HMAC
A hash is a fixed-size fingerprint of your input. An HMAC (hash-based message authentication code) combines the input with a secret key, so only parties who know the secret can recreate the same signature. This is how many tokens and webhooks prove authenticity.
Why SHA-256 and not MD5
MD5 is cryptographically broken and is not offered here. For verification, checksums, tokens and signatures, prefer a member of the SHA-2 family such as SHA-256. These hashes are computed locally with the browser's Web Crypto API and never leave your machine.
QA uses
- Verify a webhook payload signature when debugging integrations.
- Confirm two files or payloads produce the same content or fingerprint.
- Check that your app returns a deterministic hash for the same input.
- Build expected HMAC values to test signature verification logic.
Security note: Hashes do not hide content. Anyone can recompute a hash of plain text and look it up. Never use this tool with real passwords or secrets.