HMAC
Hash-based Message Authentication Code: a construction that combines a secret key with a cryptographic hash to verify both integrity and authenticity of a message.
HMAC (Hash-based Message Authentication Code) wraps a hash function like SHA-256 with a shared secret key to produce an authentication tag that proves the message was not tampered with and came from someone holding the key. The construction (`H((K xor opad) || H((K xor ipad) || message))`) is provably secure even against length-extension attacks that break naive `H(K || message)` schemes. HMAC is everywhere: AWS request signing (SigV4), JWT HS256 tokens, webhook signatures (Stripe, GitHub), TLS record MACs in older cipher suites, and TOTP/HOTP one-time codes. The right primitive any time both sides share a secret and need to authenticate messages.
Reference
Related terms
See also
Referenced on
- API Key Generator, Free Online, Strong Random Tokens
- Argon2 Hash Generator, Free Online, OWASP Recommended
- Django Password Hash Generator, Free Online, PBKDF2 SHA-256
- DNS Zone Transfer Attack (AXFR): How a Single Query Exposes Your Entire Domain
- HMAC Generator, Free Online, MD5/SHA-1/256/512
- JWT Secret Generator, Free Online, HS256/HS384/HS512
- MD5 Hash Generator, Free Online, Browser-Based
- Password Tools, Free Online Generators & Hash Utilities
- PBKDF2 Generator, Free Online, Custom Iterations
- SHA-1 Hash Generator, Free Online, Browser-Native
- SHA-256 Generator Free Online, Hash Text or Files
- SHA-3 Generator Free Online, SHA3-224/256/384/512
- SHA-512 Generator, Free Online, HMAC Support
- Terms of Service - DNS Checker