Skip to content
FlexibleToolsAI
Security Toolkit · 100% Client-Side Private

Webhook Signature Generator & Verifier

Debug webhook signature verification. Pick the provider, enter your signing secret and the raw request body, and get the exact signature headers the provider would send — plus a ready-to-run curl command. Paste a received header to see whether it verifies.

Choose GitHub, Stripe, Slack, Shopify, Standard Webhooks (Svix) or Twilio, enter the signing secret, timestamp and raw body, and the tool computes the provider's HMAC exactly as documented and shows the headers. Paste the signature you received to check it, with a warning if the timestamp is too old.

HMAC-SHA256 of the body, hex, prefixed with “sha256=”. Signs: raw request body. Header: X-Hub-Signature-256.

must be the exact raw bytes received — don't re-serialise JSON

Verify a signature you received

Common reasons verification fails: parsing and re-stringifying the JSON before hashing (use the raw body), the wrong secret (test vs live), trimming whitespace, or comparing with == instead of a constant-time comparison. Everything here runs in your browser.

Zero Server Uploads

Files process in local RAM

Instant WASM Speed

No waiting queues or lags

Unlimited Batching

Convert files without limits

Suggest a Feature or Improvement for Webhook Signature Generator

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use Webhook Signature Generator

  1. 1Choose the provider format.
  2. 2Enter the webhook signing secret.
  3. 3Paste the raw request body (and timestamp if required).
  4. 4Copy the headers, or paste a received signature to verify it.

How providers sign webhooks

GitHub sends X-Hub-Signature-256: sha256=HMAC(body). Stripe signs “timestamp.body” and sends t=…,v1=…. Slack signs “v0:timestamp:body”. Shopify sends a Base64 HMAC of the body. Standard Webhooks (used by Svix, Resend, Clerk and others) signs “id.timestamp.body” with a Base64 secret prefixed whsec_.

Including a timestamp in the signed data lets receivers reject replays; most allow five minutes.

Why verification fails

Almost always the body: frameworks parse JSON and re-serialise it, changing whitespace or key order, so the HMAC differs. Verify against the raw bytes before parsing. Also check you're using the right secret (test vs live, per-endpoint secrets) and compare signatures in constant time. For generic HMACs use the HMAC Generator.

Frequently Asked Questions

Is my signing secret safe here?

Yes — signatures are computed in your browser and nothing is sent to our server. Still, prefer test-mode secrets when debugging.

Why does Stripe's signature include a timestamp?

So an attacker can't replay an old, validly signed event later. Reject events whose timestamp is more than a few minutes old.

Is it free? Do I need an account?

It's completely free with no sign-up and no daily credits.

Related Tools