#519 · Developer Tool

HMAC Verifier

HMAC Verifier processes UTF-8 text locally and returns a copy-ready result without a network request. The verifier recomputes an HMAC for the message and secret, decodes the expected tag, and compares equal-length byte arrays without early exit. The page reports the byte length, selected parameters, and output size so that the same operation can be reproduced in code or at the command line.

Developer Input

Local browser processing
Ad space

How to use this developer tool

  1. Enter or paste the exact source text.
  2. Choose the algorithm parameters and output encoding.
  3. Run the operation or press Ctrl/Cmd + Enter.
  4. Copy or download the result and compare it with the consuming system.

What this developer tool does

A valid result means the supplied tag matches the message and key under the selected HMAC hash. It does not establish how securely the secret was stored or transported.

The page converts the input to UTF-8 bytes, applies HMAC, and serializes the resulting bytes in the selected output encoding.

Whitespace, line endings, character normalization, salts, and keys are part of the input. Preserve them exactly when reproducing a result.

Example

Input

signed webhook body

Result

The output panel shows the computed value plus byte and parameter statistics.

Use cases

  • Reproduce a digest or derived value while debugging an integration.
  • Build fixtures for unit tests and API examples.
  • Check that two implementations use identical byte encodings and parameters.
  • Prepare copy-ready values for local development configuration.

Tips for reliable output

  • Compare bytes and encodings, not only visible characters.
  • Keep salts and keys separate from the message.
  • Record every selected parameter with a test vector.
  • Do not trim whitespace unless the protocol requires it.
  • Use a password-specific KDF for stored passwords.

Processing details

The verifier recomputes an HMAC for the message and secret, decodes the expected tag, and compares equal-length byte arrays without early exit. Input stays in memory for the duration of the page session. The displayed processing time is measured in the browser and varies by device.

Browser text input is UTF-8 and the secret is treated as text. Real webhook systems often require the untouched raw request bytes; parsing and re-serializing a body can invalidate a correct signature.

Frequently asked questions

Does the HMAC Verifier send input to a server?

No. The calculation runs in the current browser tab and the page does not upload the entered text.

Can I compare the HMAC Verifier output with a command-line result?

Yes. Select the same text encoding and output format, then compare the hexadecimal or Base64 value byte for byte.

Why does changing one character produce a different HMAC value?

Cryptographic hash and derivation functions are built to spread a small input change across the resulting bytes.

Does HMAC Verifier encrypt or hide the original data?

No. A digest or derived key is not encryption and cannot be decrypted back into its input.

How is Unicode text handled by HMAC Verifier?

Text is converted to UTF-8 bytes before processing, so visually similar but differently normalized strings may produce different results.

Operation reference

StageBehavior
InputUTF-8 bytes
OutputHex or Base64

More Hash, ID & Security tools

Browse the Hash, ID & Security category