แฮช/การเข้ารหัส
HMAC Generator
คำนวณ HMAC (Hash-based Message Authentication Code) ของข้อความหรือไฟล์ด้วยคีย์ลับ — พร้อมกันแปดอัลกอริทึม: MD5, SHA-1, SHA-256, SHA-384, SHA-512, SHA3-256, SHA3-512, RIPEMD-160
HMAC (Hash-based Message Authentication Code) is a hash computed together with a secret key, proving a message hasn't changed and was sent by someone who knows that key. Unlike a plain hash, an HMAC can't be forged without knowing the secret.
How to use it
- Enter text or a file and a secret key — the HMAC is computed instantly with eight algorithms at once (MD5, SHA-1, SHA-2, SHA3, RIPEMD-160).
- Copy the variant you need to verify a signature or compare against an expected value.
- The same input and key always produce the same HMAC — handy for checking against a signature received from another system.
Common uses
- Verifying a webhook signature from a payment service or API (most sign the payload with HMAC-SHA256).
- Generating a request signature for an API that requires HMAC authentication.
- Debugging a mismatched signature — checking the key, input encoding, and algorithm one at a time.
Things to keep in mind
HMAC protects against tampering and confirms the sender's authenticity, but it doesn't encrypt the message itself — the content stays readable.
A mismatched HMAC is most often caused by different data encoding (e.g. JSON field order) or a stray whitespace or line break, not by a bug in the algorithm itself.
บทความเกี่ยวกับเครื่องมือนี้: HMAC: แฮชที่มีคีย์ต่างจากแฮชธรรมดาอย่างไร
คำถามที่พบบ่อย
HMAC ต่างจากแฮชธรรมดาอย่างไร?
แฮชธรรมดาพิสูจน์เพียงว่าข้อมูลไม่ถูกเปลี่ยนแปลง ส่วน HMAC ใช้คีย์ลับเพิ่มเติม จึงพิสูจน์ทั้งความถูกต้องและว่าผู้ส่งรู้ความลับที่ใช้ร่วมกัน — หากไม่มีคีย์ ใครก็ไม่สามารถสร้าง HMAC ที่ถูกต้องได้แม้จะรู้อัลกอริทึม
ควรเลือกอัลกอริทึมแฮชแบบไหนสำหรับ HMAC?
HMAC-SHA256 เป็นค่าเริ่มต้นที่ทันสมัยและมั่นคง ตัวเลือกเก่าอย่าง HMAC-MD5 หรือ HMAC-SHA1 ในฐานะ HMAC เองยังไม่ถูกเจาะ แต่แนะนำให้ใช้ SHA-256 ขึ้นไปสำหรับระบบใหม่
คีย์ลับของฉันถูกส่งไปที่ไหนหรือไม่?
ไม่ HMAC ถูกคำนวณทั้งหมดในเบราว์เซอร์ของคุณผ่าน Web Crypto API คีย์และข้อความจะไม่ออกจากอุปกรณ์ของคุณเลย
เหตุใดจึงไม่ควรเปรียบเทียบ HMAC ด้วยตัวดำเนินการเปรียบเทียบค่าเท่ากันแบบธรรมดา?
การเปรียบเทียบสตริงแบบธรรมดาจะหยุดทำงานทันทีที่พบความไม่ตรงกันแรก และเวลาที่ใช้จะเผยให้ผู้โจมตีรู้ว่าเขาเดาอักขระตัวแรก ๆ ถูกกี่ตัว (timing attack) จำเป็นต้องใช้ฟังก์ชันเปรียบเทียบแบบเวลาคงที่ เช่น hash_equals ใน PHP
สามารถใช้คีย์เดียวกันสำหรับหลายจุดประสงค์ที่แตกต่างกันได้หรือไม่?
ไม่แนะนำ หากคีย์ลับเดียวกันถูกใช้ทั้งสำหรับเซ็นชื่อ webhook และจุดประสงค์อื่น การถูกเจาะระบบหนึ่งจะทำให้ระบบอื่นถูกเจาะไปด้วยโดยอัตโนมัติ — ควรสร้างคีย์แยกต่างหากสำหรับแต่ละจุดประสงค์