HMAC needs a key as well as a message

Plain SHA-256 hashes message bytes. HMAC-SHA-256 calculates an authentication value from a key and a message. RFC 2104’s construction is not simply hashing a key prepended to the message. A matching unkeyed hash alone does not authenticate the sender.

SHA-256 takes a message; HMAC-SHA-256 takes a key and a message. Both outputs are 256 bits
M is the message; K is the key. Original conceptual diagram of the inputs. Equal output length does not mean equal values or functionality.

RFC 2104 §2: HMAC

Reproduce the RFC test key as bytes

RFC 4231 test case 1 uses twenty 0x0b bytes and the message Hi There. The code below imports a Web Crypto HMAC key and prints the result in hexadecimal. Repeating the text 0b twenty times produces 40 bytes, a different input. This is a public test key, not a production secret.

Moyoutil’s hash tool calculates plain SHA hashes and has no HMAC input. The code below is a separate JavaScript example, not a complete login or webhook verification system. Real authentication requires secret-key protection and a correct verification process.

const hex = bytes => Array.from(new Uint8Array(bytes),
  n => n.toString(16).padStart(2, '0')).join('');
const keyBytes = new Uint8Array(20).fill(0x0b);
const message = new TextEncoder().encode('Hi There');
const key = await crypto.subtle.importKey(
  'raw', keyBytes, {name:'HMAC', hash:'SHA-256'},
  false, ['sign']);
const mac = await crypto.subtle.sign('HMAC', key, message);
console.log(hex(mac));
// b0344c61d8db38535ca8afceaf0bf12b
// 881dc200c9833da726e9376c2e32cff7

RFC 4231 §4.2: Test Case 1

W3C Web Cryptography: HMAC

Frequently Asked Questions

Can I compare results just because both names contain SHA-256?

Do not confuse plain SHA-256 with HMAC-SHA-256. Comparing HMAC values requires the same key bytes, message bytes, and algorithm. Also distinguish output encodings such as hexadecimal and Base64.