HMAC needs a key as well as a message
Plain SHA-256 hashes message bytes. HMAC-SHA-256 calculates an authentication value from a key and a message. RFC 2104’s construction is not simply hashing a key prepended to the message. A matching unkeyed hash alone does not authenticate the sender.
Reproduce the RFC test key as bytes
RFC 4231 test case 1 uses twenty 0x0b bytes and the message Hi There. The code below imports a Web Crypto HMAC key and prints the result in hexadecimal. Repeating the text 0b twenty times produces 40 bytes, a different input. This is a public test key, not a production secret.
Moyoutil’s hash tool calculates plain SHA hashes and has no HMAC input. The code below is a separate JavaScript example, not a complete login or webhook verification system. Real authentication requires secret-key protection and a correct verification process.
const hex = bytes => Array.from(new Uint8Array(bytes),
n => n.toString(16).padStart(2, '0')).join('');
const keyBytes = new Uint8Array(20).fill(0x0b);
const message = new TextEncoder().encode('Hi There');
const key = await crypto.subtle.importKey(
'raw', keyBytes, {name:'HMAC', hash:'SHA-256'},
false, ['sign']);
const mac = await crypto.subtle.sign('HMAC', key, message);
console.log(hex(mac));
// b0344c61d8db38535ca8afceaf0bf12b
// 881dc200c9833da726e9376c2e32cff7Frequently Asked Questions
Can I compare results just because both names contain SHA-256?
Do not confuse plain SHA-256 with HMAC-SHA-256. Comparing HMAC values requires the same key bytes, message bytes, and algorithm. Also distinguish output encodings such as hexadecimal and Base64.