UUID Studio

HMAC-SHA256

Keyed SHA-256 message authentication.

  • đź”’ No data stored or uploaded
  • ⚡ 100% client-side
  • 🆓 Free, no account
Click Convert when ready

Override only when Auto cannot parse your paste. Changing this loads a matching sample into Input — click Convert to run. Use Load sample to cycle every format example.

All conversions

Read-only representations of the same 16 bytes. Every textual form is listed here, not in “Prefer format”.

Paste two values: if both sides are valid JSON, a structural diff appears; otherwise UUID / bytes are compared when both decode to the same format.

A
B

Create or edit JSON here (syntax colors), then format, validate, or convert - same as MongoDB $binary UUID blobs on the Convert tab once detected.

New document

Hash, HMAC, AES-GCM/CBC + RSA-OAEP, codecs, JWT decoding, UUID v4, and secure random - all client-side. JWTs use Base64URL (three segments), not a single MIME Base64 block - use Decode JWT below, not raw Base64 decode.

Examples

  • Message
    request-body

About HMAC-SHA256

A plain hash proves data wasn't corrupted; an HMAC proves it came from someone who knows a shared secret. That distinction is the whole point of webhook signatures and API request signing.

Supply a message and a secret key to get an HMAC-SHA256 digest - the same construction GitHub, Stripe, and most webhook providers use to let you verify a payload actually came from them. The key field never leaves your browser.

FAQ

Where do I put the secret?
Use the Key / passphrase field - it never leaves your browser.