Tạo Chữ Ký Khóa Bí Mật HMAC
Tạo chuỗi chữ ký xác thực HMAC (Hash-based Message Authentication Code) từ thông điệp và khóa bí mật bằng các thuật toán SHA-256, SHA-512, SHA-1 hoặc MD5.
HMAC Generator
Output (hex)
Cách thức hoạt động
Nhập dữ liệu của bạn
Điền các giá trị cần thiết, dán văn bản hoặc tải lên tệp bạn muốn xử lý.
Xem kết quả tức thì
Hầu hết các công cụ cập nhật theo thời gian thực khi bạn nhập liệu; một số công cụ sử dụng một nút hành động duy nhất.
Sử dụng kết quả
Sao chép, tải xuống hoặc chia sẻ kết quả được tạo — bạn luôn có toàn quyền kiểm soát dữ liệu của mình.
Tạo Chữ Ký Khóa Bí Mật HMAC là gì?
Compute a Hash-based Message Authentication Code (HMAC) for a message and secret key, using the browser's built-in Web Crypto API.
How to generate an HMAC
HMAC vs. a plain hash
A plain hash (like SHA-256) only proves a message wasn't altered, but anyone can compute it. An HMAC mixes in a secret key, so only someone who knows that key can produce or verify a matching code — proving both integrity and that the sender knew the secret.
How to use it
- Enter the message to authenticate.
- Enter the shared secret key.
- Pick SHA-256, SHA-384, or SHA-512, and copy the resulting hex digest.
Choosing an algorithm
SHA-256 is the most common default and is what most APIs expect (for example, AWS request signing and many webhook signature schemes). SHA-384 and SHA-512 produce longer digests for services that specifically require them.
Digest format
The tool signs the UTF-8 message with the UTF-8 secret through Web Crypto and returns lowercase hexadecimal for SHA-256, SHA-384, or SHA-512.
Secret handling notes
The secret key and message are used only in the browser Web Crypto call. Clear them before leaving a shared device or screen.
Các Câu Hỏi Thường Gặp (FAQ)
Is HMAC the same as encryption?
No. HMAC is one-way, like a hash — it authenticates a message but doesn't hide or encrypt its contents.
Is my secret key sent anywhere?
No. The HMAC is computed locally with the browser's Web Crypto API; the key and message never leave your device.
Which algorithm should I pick?
SHA-256 unless the service you're integrating with specifically documents SHA-384 or SHA-512.
Can I verify an HMAC with this tool?
Yes. Generate the HMAC from the same message, secret, and algorithm, then compare the hex digest with the expected value.
Công Cụ Liên Quan
- Khả dụngCục bộ
Trình Tạo Mật Khẩu Mạnh & Cụm Mật Khẩu (Passphrase)
Tạo mật khẩu ngẫu nhiên có độ bảo mật cao hoặc cụm mật khẩu dễ nhớ, an toàn.
- Khả dụngCục bộ
Tạo Mã Băm (Hash MD5, SHA-256...)
Tạo mã băm băm bảo mật MD5, SHA-1, SHA-256, SHA-512 từ văn bản.
- Khả dụngCục bộ
Trình Xem & Xóa Metadata EXIF Ảnh
Kiểm tra thông số máy ảnh và xóa siêu dữ liệu EXIF cùng tọa độ vị trí GPS khỏi ảnh.
- Khả dụngCục bộ
Trình Tạo Header Content Security Policy (CSP)
Thiết lập các quy tắc chính sách bảo mật header CSP nhằm ngăn chặn tấn công XSS.
- Khả dụngCục bộ
Giải Mã Chứng Chỉ SSL/TLS X.509
Phân tích tệp chứng chỉ PEM để xem tên miền (SANs), nhà cấp (CA) và hạn sử dụng.
- Khả dụngCục bộ
Phân Tích Header Email
Kiểm tra đường đi của thư, xác thực SPF, DKIM, DMARC và thời gian trễ nhận thư.
- Khả dụngMáy chủ
Kiểm Tra Rò Rỉ Mật Khẩu
Kiểm tra xem mật khẩu của bạn đã từng bị lộ trong các vụ rò rỉ dữ liệu hay chưa.
- Khả dụngMáy chủ
Quét Header Bảo Mật Web
Kiểm tra các tiêu đề bảo mật HTTP của website: HSTS, CSP, X-Frame-Options...
- Khả dụngCục bộ
Trình Tạo & Kiểm Tra Khóa SSH (Ed25519 & RSA)
Tạo cặp khóa SSH (Ed25519 / RSA) an toàn hoặc kiểm tra fingerprint của khóa công khai.
- Khả dụngCục bộ
Máy Tính Phần Trăm Đa Năng
Tính tỷ lệ phần trăm của một số, tỷ lệ tăng trưởng, giảm giá, chiết khấu và độ lệch.