Sig Check

Why your webhook signature fails.

Paste a webhook body, your signing secret, and the signature you received. When it doesn't match, the tool re-signs under each common mistake (re-serialised JSON, a stray newline, a missing timestamp) and tells you which one it was.

Header Stripe-Signature·HMAC SHA-256·Encoded as hex·Signs <timestamp>.<body>

Endpoint signing secret, starts with whsec_

Result

Add a body, a secret, and the signature header to check.

It tells you why, not just no

On a mismatch it re-signs your payload under each common mistake (re-serialised JSON, a stray newline, a missing timestamp prefix, the wrong hash) and names the one that reproduces your signature.

Four schemes, one form

Stripe signs t.body as hex, Slack signs v0:t:body, Shopify sends base64, GitHub prefixes sha256=. Paste the header and the differences are handled for you.

Secrets stay in the tab

HMAC runs on the Web Crypto API in your browser. There is no backend to send a signing secret to. Paste a live whsec_ without thinking about it.