Free Tool

Webhook Tester

Inspect inbound webhook payloads.

Payload
Result
Choose a provider, paste the secret and the raw body, then press Compute Signature. The result appears here.
Why This Runs Client Side
Your webhook secret is the most sensitive credential in the integration. This tool signs and verifies inside your browser using the Web Crypto API. Nothing is sent to any server.
The Discipline

An Unverified Webhook Is A Public Endpoint.

Every payment confirmation, every Meta lead, every Shopify order arrives as a webhook. If you do not verify the signature before you write to the database or fire a conversion, you are trusting whoever knows the URL. Attackers know the URL.

This tool computes the exact signature the sender would produce, so you can prove your verification code is correct before you go live, and debug the day a real webhook starts failing.

Rules Of Safe Webhook Handling
  • Verify Before You Parse. Compute HMAC On The Raw Bytes, Not On JSON.parse Output.
  • Use Timing Safe Compare. A Simple === Leaks The Signature One Byte At A Time.
  • Check The Timestamp. Reject Anything Older Than Five Minutes To Block Replay.
  • Return 200 Fast. Acknowledge Within Two Seconds, Then Process Async.

Every fraud incident we have audited started with an unverified webhook or a signature check that compared strings the wrong way.

Shopify

Order Paid And Fulfilment

Header X-Shopify-Hmac-Sha256, base64 encoded HMAC of the raw body. Reject the request if the base64 lengths differ.

Razorpay

Payment Captured

Header X-Razorpay-Signature, hex encoded HMAC SHA256. Same secret you configured in the dashboard, not the API key.

Meta CAPI

Conversions API

Header X-Hub-Signature-256 with sha256= prefix. Signed with the App Secret, never the Page or Ad Account token.

Common Mistakes

Verifications That Fail Silently.

  • Signing Parsed JSON. Node Re Serialises With Different Spacing. Always Hold The Raw Bytes.
  • Framework Body Parsers. Express And Fastify Consume The Body. Use A Raw Buffer Route.
  • Wrong Encoding. Hex Versus Base64. Match The Provider Exactly.
  • Case Sensitive Headers. Read Headers Case Insensitively. Cloudflare Lowercases Everything.
  • No Idempotency. Providers Retry On 5xx. Dedupe By Event ID In Your Database.
Where This Tool Fits
  1. Before Launch. Prove Your Verification Code Matches The Provider Byte For Byte.
  2. During Incident Response. Rebuild The Signature Locally And Compare Against The Failing Request.
  3. Secret Rotation. Test The New Secret Against A Sample Payload Before You Ship It To Production.
  4. Third Party Debugging. When A Provider Says The Signature Is Wrong, Show Them The Exact Bytes You Signed.