Webhook Payload HMAC-SHA256 Signature Generator & Secret Verifier
Generate and verify cryptographic HMAC-SHA256, HMAC-SHA1, and HMAC-SHA512 webhook signatures for Stripe, GitHub, Shopify, Slack, and custom APIs. Debug signature header mismatches, raw payload whitespaces, and timestamp replay attacks.Documentation & FAQs ↓
Verify Incoming Request Header
Generating signature...
const stripe = require('stripe')(process.env.STRIPE_SECRET_KEY);
try {
const event = stripe.webhooks.constructEvent(
req.body,
req.headers['stripe-signature'],
'whsec_9b7c846d1e4a3b7c846d1e4a3b7c846d'
);
console.log('Verified Stripe Event:', event.type);
} catch (err) {
console.error('Signature failure:', err.message);
}import stripe
try:
event = stripe.Webhook.construct_event(
payload=request.data,
sig_header=request.headers.get('stripe-signature'),
secret='whsec_9b7c846d1e4a3b7c846d1e4a3b7c846d'
)
except ValueError as e:
raise eStep-by-Step Instructions
4 Steps to CompletionSelect your webhook provider profile (Stripe, GitHub, Shopify, or Custom HMAC).
Paste the shared webhook secret key and raw request payload JSON into the input fields.
Optional: Provide the received webhook signature header to perform an instant verification comparison.
Inspect the calculated hex/base64 HMAC signature, comparison result, and copy-ready server verification code snippets (Node.js, Python, Go).
Practical Use Cases & Real-World Scenarios
Multi-Platform Signature Header Presets
Preconfigured header schemes for Stripe (t=...,v1=...), GitHub (sha256=...), Shopify (X-Shopify-Hmac-Sha256), and standard hex/base64 outputs.
Raw Payload Whitespace & Byte Verification
Explains and highlights invisible JSON whitespace differences, line breaks (\r\n vs \n), and character encodings that break HMAC signatures.
Hardware-Accelerated Web Crypto HMAC
Computes cryptographic hashes instantly in client memory using window.crypto.subtle.sign('HMAC', ...) with zero external API calls.
Timestamp Tolerance & Replay Protection Simulator
Tests unix timestamp tolerance windows (e.g. 5-minute Stripe tolerance) to guard against replay attacks and clock drift.
Frequently Asked Questions
Why does webhook signature verification fail in Express or Next.js even when the secret is correct?↓
How does Stripe's timestamped webhook signature prevent replay attacks?↓
Is my shared webhook secret safe when testing in this tool?↓
What is the difference between Hex and Base64 HMAC encoding?↓
Why should webhook verification use timing-safe string comparison?↓
15 Best Automation Testing Tools & Software in 2026
Dive deeper into the foundational technical concepts behind this tool on our editorial blog. Includes comprehensive hardware benchmarks, case studies, and best practices.
Found this tool helpful? Share it with colleagues & friends:
100% free, private in-browser utility with zero server uploads.
