Skip to content

Webhook Payload Inspector

Analyze webhook payloads with formatted JSON view, HMAC signature verification, timestamp detection, and cURL reconstruction

Webhook Payload Inspector

5 headers
359 bytes
Payload viewapplication/json
{
  "event": "payment.success",
  "data": {
    "object": {
      "id": "pay_1234567890",
      "amount": 4999,
      "currency": "usd",
      "status": "succeeded",
      "created": 1707734400
    },
    "customer": {
      "id": "cus_ABC123",
      "email": "user@example.com"
    }
  },
  "timestamp": 1707734400,
  "signature": "v1,bm9yZXBsYXlhdHRhY2tz"
}
Analysis
Size statistics
Body
359 B
Headers
178 B
Total
537 B
Gzip (est.)
~108 B
Detected timestamps
$.data.object.created1707734400
Feb 12, 2024, 10:40:00 AM UTC
$.timestamp1707734400
Feb 12, 2024, 10:40:00 AM UTC
Signature verifier
Algorithm:
cURL command
curl -X POST 'https://example.com/webhook' \
  -H 'Content-Type: application/json' \
  -H 'X-Hub-Signature-256: sha256=abc123def456' \
  -H 'User-Agent: GitHub-Hookshot/abc123' \
  -H 'X-GitHub-Event: push' \
  -H 'X-Request-ID: 550e8400-e29b-41d4-a716-446655440000' \
  -d '{
  "event": "payment.success",
  "data": {
    "object": {
      "id": "pay_1234567890",
      "amount": 4999,
      "currency": "usd",
      "status": "succeeded",
      "created": 1707734400
    },
    "customer": {
      "id": "cus_ABC123",
      "email": "user@example.com"
    }
  },
  "timestamp": 1707734400,
  "signature": "v1,bm9yZXBsYXlhdHRhY2tz"
}'

Updated . Provided as is. Check the output before you rely on it in production.

How to use Webhook Payload Inspector

  1. 1

    Paste headers and body

    Paste the raw request headers (one per line) and the payload body, or load the sample webhook.

  2. 2

    Inspect the payload

    View the body formatted or as a hex dump, with size statistics for the body and the full request.

  3. 3

    Check timestamps

    Timestamps found in headers and body are decoded to readable dates, which helps spot replayed or stale deliveries.

  4. 4

    Verify the signature

    Enter the HMAC secret and the expected signature, choose the algorithm and verify.

  5. 5

    Replay with cURL

    Copy the reconstructed cURL command to replay the request against your endpoint.

Questions and answers

What is Webhook Payload Inspector?
A webhook is an HTTP POST a service sends to your endpoint when an event happens, usually a JSON body plus a signature header. This tool parses pasted headers and body, pretty-prints the JSON, finds Unix timestamps, checks an HMAC-SHA256 or SHA-1 signature against your secret and rebuilds the request as cURL.
Does Webhook Payload Inspector store or send my data?
No. All processing happens entirely in your browser. Your webhook payloads and secrets stay on your device — nothing is sent to any server.
Which webhook providers does Webhook Payload Inspector support?
Any provider that signs the raw body with HMAC-SHA256 or HMAC-SHA1 as a hex digest, such as GitHub; sha256= and sha1= prefixes are stripped. Stripe and Slack sign a timestamp-prefixed string, so paste that string as the payload. Ed25519 signatures, used by Discord, are not supported.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/webhook-inspector/

For automation planning, fetch the canonical contract at /api/tool/webhook-inspector.json.