Webhook Signature Verifier
Verify a webhook's HMAC-SHA256 or HMAC-SHA1 signature against your signing secret, and inspect its headers, JSON body and timestamps.
Webhook Signature Verifier
{ "event": "payment.success", "data": { "object": { "id": "pay_1234567890", "amount": 4999, "currency": "usd", "status": "succeeded", "created": 1707734400 }, "customer": { "id": "cus_ABC123", "email": "user@example.com" } }, "timestamp": 1707734400, "signature": "v1,bm9yZXBsYXlhdHRhY2tz" }
curl -X POST 'https://example.com/webhook' \
-H 'Content-Type: application/json' \
-H 'X-Hub-Signature-256: sha256=abc123def456' \
-H 'User-Agent: GitHub-Hookshot/abc123' \
-H 'X-GitHub-Event: push' \
-H 'X-Request-ID: 550e8400-e29b-41d4-a716-446655440000' \
-d '{
"event": "payment.success",
"data": {
"object": {
"id": "pay_1234567890",
"amount": 4999,
"currency": "usd",
"status": "succeeded",
"created": 1707734400
},
"customer": {
"id": "cus_ABC123",
"email": "user@example.com"
}
},
"timestamp": 1707734400,
"signature": "v1,bm9yZXBsYXlhdHRhY2tz"
}'Updated . Provided as is. Check the output before you rely on it in production.
How to use Webhook Signature Verifier
- 1
Paste the request
Paste the webhook's raw headers and body exactly as received. Signatures are computed over the raw body, so do not re-format it.
- 2
Enter the secret and signature
Enter your webhook signing secret and the signature from the request header, and pick the HMAC algorithm.
- 3
Verify
Run Verify to compare the computed signature with the one you received.
- 4
Check freshness and replay
Review the decoded timestamps to reject stale deliveries, and copy the reconstructed cURL command to replay the request.
Questions and answers
What is Webhook Signature Verifier?
Why does my signature not match?
Is my signing secret sent anywhere?
For AI agents: how to call this tool
Machine-readable contract, endpoints and examples. Humans can ignore this section.
Best Path For Builders
Browser workflow
Runs instantly in the browser with private local processing and copy/export-ready output.
Browser Workflow
This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.
/webhook-signature-verifier/
For automation planning, fetch the canonical contract at /api/tool/webhook-signature-verifier.json.