Skip to content

Webhook Signature Verifier

Verify a webhook's HMAC-SHA256 or HMAC-SHA1 signature against your signing secret, and inspect its headers, JSON body and timestamps.

Webhook Signature Verifier

5 headers
359 bytes
Payload viewapplication/json
{
  "event": "payment.success",
  "data": {
    "object": {
      "id": "pay_1234567890",
      "amount": 4999,
      "currency": "usd",
      "status": "succeeded",
      "created": 1707734400
    },
    "customer": {
      "id": "cus_ABC123",
      "email": "user@example.com"
    }
  },
  "timestamp": 1707734400,
  "signature": "v1,bm9yZXBsYXlhdHRhY2tz"
}
Analysis
Size statistics
Body
359 B
Headers
178 B
Total
537 B
Gzip (est.)
~108 B
Detected timestamps
$.data.object.created1707734400
Feb 12, 2024, 10:40:00 AM UTC
$.timestamp1707734400
Feb 12, 2024, 10:40:00 AM UTC
Signature verifier
Algorithm:
cURL command
curl -X POST 'https://example.com/webhook' \
  -H 'Content-Type: application/json' \
  -H 'X-Hub-Signature-256: sha256=abc123def456' \
  -H 'User-Agent: GitHub-Hookshot/abc123' \
  -H 'X-GitHub-Event: push' \
  -H 'X-Request-ID: 550e8400-e29b-41d4-a716-446655440000' \
  -d '{
  "event": "payment.success",
  "data": {
    "object": {
      "id": "pay_1234567890",
      "amount": 4999,
      "currency": "usd",
      "status": "succeeded",
      "created": 1707734400
    },
    "customer": {
      "id": "cus_ABC123",
      "email": "user@example.com"
    }
  },
  "timestamp": 1707734400,
  "signature": "v1,bm9yZXBsYXlhdHRhY2tz"
}'

Updated . Provided as is. Check the output before you rely on it in production.

How to use Webhook Signature Verifier

  1. 1

    Paste the request

    Paste the webhook's raw headers and body exactly as received. Signatures are computed over the raw body, so do not re-format it.

  2. 2

    Enter the secret and signature

    Enter your webhook signing secret and the signature from the request header, and pick the HMAC algorithm.

  3. 3

    Verify

    Run Verify to compare the computed signature with the one you received.

  4. 4

    Check freshness and replay

    Review the decoded timestamps to reject stale deliveries, and copy the reconstructed cURL command to replay the request.

Questions and answers

What is Webhook Signature Verifier?
A webhook signature is an HMAC of the request body computed with a shared secret, so the receiver can confirm the sender and that the body is unchanged. This tool computes HMAC-SHA256 or SHA-1 over the pasted body and compares it with the signature value. It uses the same engine as Webhook Payload Inspector.
Why does my signature not match?
The most common cause is a modified body: the signature is computed over the exact raw bytes, so parsing and re-serializing JSON, or changing whitespace, breaks it. Also confirm the algorithm and whether the provider signs a timestamp prefix.
Is my signing secret sent anywhere?
No. The HMAC is computed in your browser and the secret never leaves the page.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/webhook-signature-verifier/

For automation planning, fetch the canonical contract at /api/tool/webhook-signature-verifier.json.