./prontouso.com
BẢO MẬT & RIÊNG TƯ

Tạo Chữ Ký Khóa Bí Mật HMAC

Tạo chuỗi chữ ký xác thực HMAC (Hash-based Message Authentication Code) từ thông điệp và khóa bí mật bằng các thuật toán SHA-256, SHA-512, SHA-1 hoặc MD5.

Trạng thái công cụChạy trên trình duyệt của bạn
Xem trước

HMAC Generator

Thuật toán

Output (hex)

Cách thức hoạt động

  1. Nhập dữ liệu của bạn

    Điền các giá trị cần thiết, dán văn bản hoặc tải lên tệp bạn muốn xử lý.

  2. Xem kết quả tức thì

    Hầu hết các công cụ cập nhật theo thời gian thực khi bạn nhập liệu; một số công cụ sử dụng một nút hành động duy nhất.

  3. Sử dụng kết quả

    Sao chép, tải xuống hoặc chia sẻ kết quả được tạo — bạn luôn có toàn quyền kiểm soát dữ liệu của mình.

Quyền riêng tư & xử lý dữ liệuChạy cục bộ 100% trên trình duyệt của bạn. Công cụ này không tải dữ liệu của bạn lên máy chủ.

Tạo Chữ Ký Khóa Bí Mật HMAC là gì?

Compute a Hash-based Message Authentication Code (HMAC) for a message and secret key, using the browser's built-in Web Crypto API.

TÌM HIỂU CÁCH HOẠT ĐỘNG CỦA CÔNG CỤ

How to generate an HMAC

HMAC vs. a plain hash

A plain hash (like SHA-256) only proves a message wasn't altered, but anyone can compute it. An HMAC mixes in a secret key, so only someone who knows that key can produce or verify a matching code — proving both integrity and that the sender knew the secret.

How to use it

  • Enter the message to authenticate.
  • Enter the shared secret key.
  • Pick SHA-256, SHA-384, or SHA-512, and copy the resulting hex digest.

Choosing an algorithm

SHA-256 is the most common default and is what most APIs expect (for example, AWS request signing and many webhook signature schemes). SHA-384 and SHA-512 produce longer digests for services that specifically require them.

Digest format

The tool signs the UTF-8 message with the UTF-8 secret through Web Crypto and returns lowercase hexadecimal for SHA-256, SHA-384, or SHA-512.

Secret handling notes

The secret key and message are used only in the browser Web Crypto call. Clear them before leaving a shared device or screen.

Các Câu Hỏi Thường Gặp (FAQ)

Is HMAC the same as encryption?

No. HMAC is one-way, like a hash — it authenticates a message but doesn't hide or encrypt its contents.

Is my secret key sent anywhere?

No. The HMAC is computed locally with the browser's Web Crypto API; the key and message never leave your device.

Which algorithm should I pick?

SHA-256 unless the service you're integrating with specifically documents SHA-384 or SHA-512.

Can I verify an HMAC with this tool?

Yes. Generate the HMAC from the same message, secret, and algorithm, then compare the hex digest with the expected value.

Công Cụ Liên Quan