pwnsy
Runs on your device

Webhook Signature Checker

Paste a webhook body, its signature header and your signing secret. The Webhook Signature Checker recomputes the HMAC the way the provider does, says whether it matches, and when it does not, tests the usual mistakes and names the one that explains it. It also signs test payloads for your own endpoint and writes the verify code.

Paste the body exactly as received. Spaces, key order and a final newline all change the signature.
Examples

The HMAC is computed with your browser's Web Crypto API. Nothing you type is sent. Use a test or staging secret where you can.

How webhook signatures work

The provider and your server share a secret. For each event, the provider computes an HMAC over the raw body, often with a timestamp or message id in front, and sends it in a header. Your server computes the same HMAC over the bytes it received and compares. A match proves the request came from someone holding the secret and was not changed on the way.

  • Verify mode rebuilds the exact string the provider signs, shows it with hidden whitespace marked, and compares in constant time.
  • On a mismatch it retries with the common mistakes: JSON re-serialized by a framework, a newline added or dropped, Windows line endings, the whsec_ prefix kept or stripped, a base64 secret used as text, hex compared with base64, and seconds mixed with milliseconds.
  • Sign mode builds valid headers for a payload so you can test your own endpoint, with a ready curl command.
  • Verify code for Node.js and Python follows each match, using constant-time comparison and a replay window.

Signing schemes

Webhook signature FAQ

Why does my webhook signature not match?

Most often the server verifies a body that a framework has already parsed and re-serialized as JSON, which changes spacing and key order. Sign and compare the raw bytes as received. The next most common causes are the wrong secret (test versus live, or one endpoint's secret on another), a trailing newline added by a tool, and comparing hex against base64.

Is it safe to paste my webhook secret here?

The page computes the HMAC with the browser's Web Crypto API and sends nothing. Even so, use a test-mode or staging secret where you can, and roll any secret that has been pasted into a shared machine or chat.

Why check the timestamp as well as the signature?

A valid signed request can be captured and sent again. Providers that sign a timestamp, such as Stripe, Slack and Svix, expect you to reject requests older than a few minutes, and to dedupe on the event id so a replay inside the window does nothing.

Should I compare signatures with ===?

No. A plain string comparison stops at the first different character, which leaks timing. Use crypto.timingSafeEqual in Node or hmac.compare_digest in Python, after checking the lengths match. The code on this page does that.

Signing schemes follow each provider's webhook documentation as of October 2026. Where a provider ships an SDK verifier, use it in production; the code here shows what it does.

Copied