All tools

Webhook Signature Verifier (HMAC)

Network

Recompute an HMAC over a raw webhook payload and compare it to a provided signature, supporting the common sha256= prefix style (Stripe/GitHub-style webhooks) plus raw hex or base64 encoding.

Paste a webhook payload, your signing secret, and the signature a provider sent, and see whether they actually match, the exact check your own webhook receiver runs before trusting a request. It recomputes the HMAC over the raw payload with SHA-1, SHA-256, or SHA-512 and compares it against the provided signature, accepting a plain hex or base64 digest as well as the sha256= prefixed style Stripe and GitHub both use. It's built for debugging a rejected webhook, not for production request verification: use it to figure out why a signature check is failing locally before you go digging through provider docs. Nothing is transmitted anywhere; the comparison runs entirely in your browser.

webhookhmacsignaturesecurityhash

How to use Webhook Signature Verifier (HMAC)

  • 1.Paste the exact raw payload bytes your endpoint received, not a re-serialized copy (re-encoding JSON changes whitespace and breaks the HMAC).
  • 2.Enter the shared signing secret and the signature value from the request header, with or without an algorithm prefix like sha256=.
  • 3.Pick the hash algorithm the provider uses (SHA-256 is the default for most webhook providers) and check whether the result reports valid.

Frequently asked questions

Why does my signature check fail even though the secret is correct?
The most common cause is that the payload was re-serialized before hashing, for example by a framework that parses and re-stringifies JSON. HMAC is computed over the exact raw bytes received, so any whitespace or key-order difference produces a completely different signature.
Does this work for Stripe and GitHub webhooks?
Yes, both send a sha256= prefixed hex signature, which this tool detects and strips automatically before comparing. Stripe's actual header also includes a timestamp component (t=...,v1=...) that isn't parsed here, only the v1 signature value itself.
Is my secret sent to a server?
No, the HMAC is computed entirely client-side in your browser using the Web Crypto API. Nothing is transmitted or stored.
What if the provider signs a base64 digest instead of hex?
The tool checks both encodings automatically and reports which one matched, so you don't need to know in advance which format a given provider uses.

Use via API, SDK, or MCP

cURL# Free: 1,000 req/day · Pro: 10,000 req/day
curl -X POST https://api.utilix.tech/v1/tools/webhook-signature-verifier \
  -H "Authorization: Bearer utx_live_..." \
  -H "Content-Type: application/json" \
  -d '{"payload":"{\"event\":\"payment.succeeded\",\"amount\":100}","secret":"whsec_test_secret","signature":"sha256=5b8f...","algorithm":"sha256"}'

Get an API key from your dashboard · Full API docs →