Before you start
What you need
A test message, test secret, agreed SHA-2 algorithm, and output encoding.
Developer & Data
Create an HMAC test signature from a message and secret using browser Web Crypto.
No black box
The secret is imported as a non-exportable in-memory HMAC key, then Web Crypto signs the UTF-8 message.
Before you start
A test message, test secret, agreed SHA-2 algorithm, and output encoding.
What you get
An HMAC value for controlled interoperability testing.
Keep in mind
Do not paste production signing secrets. HMAC verification also depends on exact bytes, canonicalization, timestamps, and replay policy.
Practical uses
Verified data boundary
The published contract marks these tools as client-only processing. Nirmion uses the API only to confirm that this workspace is enabled in MySQL; source values and results are not sent to Flask.