Developer & Data

Calculate HMAC With Matching Keys and Output Formats

Updated

A shared secret changes a message authentication code. Two systems must agree on the message bytes, key, algorithm and output representation before their HMAC values will match.

Use HMAC Signature Generator to inspect a small example of that process. It supports SHA256 and SHA512, with hexadecimal or Base64 output.

Check an example rather than a live secret

Use key as the demonstration key and The quick brown fox jumps over the lazy dog as the message. With SHA256 and hexadecimal output, the digest is f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8.

Switching to Base64 changes the representation of the same digest bytes. It does not create a different secret or algorithm. Compare formats consistently when troubleshooting an integration.

A newline appended to the message changes its bytes. A different character encoding or a trimmed key can also explain a mismatch. Reproduce the exact agreed input rather than trying several almost identical visible strings.

Redaction is not local only processing

The plugin removes the key from its result payload and report exports. That avoids copying it into the generated report, but the WordPress server still receives it for calculation.

Use a harmless demonstration key when checking a process on a public site. Production signing secrets belong in the systems responsible for signing and verification.

This tool computes an HMAC. It does not receive a signed webhook, compare a supplied signature in a protected authentication flow or authorise a request. Those operations require suitable application code and careful byte handling.

When reporting a mismatch to another developer, share the algorithm, representation and a nonsecret test vector. That gives both sides a repeatable comparison without exposing the key used for real transactions.

Join the conversation

Your email address will not be published. Required fields are marked *

Explore Whatson tool information