CSP Builder
Build and risk-score Content-Security-Policy headers visually.
OpenGenerate HMAC signatures with Web Crypto. - runs entirely in your browser. Free, fast and private.
Load your input in the editor or upload area on the tool page.
Tune any options shown for HMAC Generator to match your task.
HMAC Generator processes everything in your browser with no upload.
Copy, download, or share the output from the results panel.
Webhook docs say "sign with HMAC-SHA256." HMAC Generator takes a secret and a message, runs the keyed hash in Web Crypto, and shows the hex or Base64 digest you can paste into a test harness.
Build signatures when you are writing a receiver, replaying a fixture, or checking that your server and a vendor agree on the canonical string. Pick the digest encoding your API expects. Hex and Base64 look different for the same bytes.
Trap: hashing JSON after your framework pretty-printed it. Most providers sign the raw body bytes. Copy the exact payload string, including whitespace, that the wire will carry.
When the vendor folds a timestamp into the signed base (GitHub, Stripe, Slack styles), switch to Webhook HMAC so the base string matches their header format.
Secret and message stay in the tab for the Web Crypto call. Close the page or clear fields when you finish with a production signing key.
Vendor formats: Webhook HMAC · Verify webhooks locally
Processes data instantly with no server round-trips.
Your data never leaves your browser. Nothing is uploaded.
Works in any modern browser. Nothing to download or install.
No limits, no sign-up, no credit card required.
Works on desktop, tablet and mobile devices.
Beautiful in both themes. Your preference is saved.
Keyboard shortcut
Mint HMAC digests while you implement verify middleware.
Reproduce a failing signature with the same secret and body.
Generate expected digests for unit tests without a CLI.
Answers for this tool. For site-wide help, open the FAQ hub.
Generators and hashers run locally. Still, never paste production secrets into any site if your security policy forbids it.
Results live in page memory until you leave or clear. Favourites/history do not save password fields unless you explicitly store them in Vault.
When applicable, tools rely on Web Crypto or well-known libraries. Read on-page notes for exact algorithms (SHA-256, bcrypt-style notes, etc.).
After load, crypto helpers typically work offline. Confirm network independence for your threat model.
Browser CSPRNG (crypto.getRandomValues) powers secure generators when the tool states so.
Treat generated secrets like passwords - share only through approved password managers, never chat apps.
OneDevToolkit aids technical workflows; it is not a certification product. See Compliance for processing model language.
Always check you are on your real OneDevToolkit domain before entering sensitive material.
Contact us via Contact with responsible-disclosure details - do not include live production secrets.