Paste a webhook body, your signing secret, and the signature you received. When it doesn't match, the tool re-signs under each common mistake (re-serialised JSON, a stray newline, a missing timestamp) and tells you which one it was.
Endpoint signing secret, starts with whsec_
Add a body, a secret, and the signature header to check.
On a mismatch it re-signs your payload under each common mistake (re-serialised JSON, a stray newline, a missing timestamp prefix, the wrong hash) and names the one that reproduces your signature.
Stripe signs t.body as hex, Slack signs v0:t:body, Shopify sends base64, GitHub prefixes sha256=. Paste the header and the differences are handled for you.
HMAC runs on the Web Crypto API in your browser. There is no backend to send a signing secret to. Paste a live whsec_ without thinking about it.