🪝Webhook Payload Signature Checker

Enter a secret, payload and signature to compute the HMAC and see whether they match

The payload must be the bytes you received. Re-indenting JSON to look tidy changes the bytes and breaks the signature.

You Might Also Need

Checking that a webhook really came from the service

Anyone who knows the URL can post to a webhook endpoint, so the signature traveling with the body has to be verified. Enter the secret, the payload you received and the signature, and the same HMAC is computed here to tell you whether they match. The computed value, the given value and a length comparison are all shown, so you can see where things diverge.

What string gets signed and what prefix it carries differ between services, and those details change. This page therefore holds no per-service format table and takes the secret, payload, encoding and signature you read from the sender documentation. The comparison matches lengths first and then walks the whole string in constant time: stopping at the first differing character leaks how many leading characters were correct.

This page cannot work out which service a signature came from, and it checks neither timestamp freshness nor replay protection. Both belong in your own handler, following the sender documentation. Everything runs in your browser and the secret is never transmitted. Written as of October 2026.

Frequently asked questions

Why does the signature format differ between services?

Each service decides what string gets signed, which header carries it, and what prefix it wears. Some fold a timestamp into the signed string and the encodings differ too. This page therefore carries no per-service format table and asks you to paste the values from the sender documentation.

I pasted the payload exactly, so why does it not match?

A single differing byte changes the result completely. Re-indented JSON, changed line endings and a trailing space are the usual culprits. Try the original body straight from your logs, untouched.

Can I just compare signatures with an equality operator?

Not advisable. A comparison that stops at the first differing character takes a different amount of time depending on how many leading characters matched, and measuring that difference lets someone guess a signature one character at a time. Matching lengths first and walking the whole string is the safer shape.