Webhook Signature Verifier (HMAC)
NetworkRecompute an HMAC over a raw webhook payload and compare it to a provided signature, supporting the common sha256= prefix style (Stripe/GitHub-style webhooks) plus raw hex or base64 encoding.
Paste a webhook payload, your signing secret, and the signature a provider sent, and see whether they actually match, the exact check your own webhook receiver runs before trusting a request. It recomputes the HMAC over the raw payload with SHA-1, SHA-256, or SHA-512 and compares it against the provided signature, accepting a plain hex or base64 digest as well as the sha256= prefixed style Stripe and GitHub both use. It's built for debugging a rejected webhook, not for production request verification: use it to figure out why a signature check is failing locally before you go digging through provider docs. Nothing is transmitted anywhere; the comparison runs entirely in your browser.
How to use Webhook Signature Verifier (HMAC)
- 1.Paste the exact raw payload bytes your endpoint received, not a re-serialized copy (re-encoding JSON changes whitespace and breaks the HMAC).
- 2.Enter the shared signing secret and the signature value from the request header, with or without an algorithm prefix like sha256=.
- 3.Pick the hash algorithm the provider uses (SHA-256 is the default for most webhook providers) and check whether the result reports valid.
Frequently asked questions
Use via API, SDK, or MCP
cURL# Free: 1,000 req/day · Pro: 10,000 req/day
curl -X POST https://api.utilix.tech/v1/tools/webhook-signature-verifier \
-H "Authorization: Bearer utx_live_..." \
-H "Content-Type: application/json" \
-d '{"payload":"{\"event\":\"payment.succeeded\",\"amount\":100}","secret":"whsec_test_secret","signature":"sha256=5b8f...","algorithm":"sha256"}'Get an API key from your dashboard · Full API docs →