Webhook Tester
Inspect inbound webhook payloads.
An Unverified Webhook Is A Public Endpoint.
Every payment confirmation, every Meta lead, every Shopify order arrives as a webhook. If you do not verify the signature before you write to the database or fire a conversion, you are trusting whoever knows the URL. Attackers know the URL.
This tool computes the exact signature the sender would produce, so you can prove your verification code is correct before you go live, and debug the day a real webhook starts failing.
- Verify Before You Parse. Compute HMAC On The Raw Bytes, Not On JSON.parse Output.
- Use Timing Safe Compare. A Simple === Leaks The Signature One Byte At A Time.
- Check The Timestamp. Reject Anything Older Than Five Minutes To Block Replay.
- Return 200 Fast. Acknowledge Within Two Seconds, Then Process Async.
Every fraud incident we have audited started with an unverified webhook or a signature check that compared strings the wrong way.
Order Paid And Fulfilment
Header X-Shopify-Hmac-Sha256, base64 encoded HMAC of the raw body. Reject the request if the base64 lengths differ.
Payment Captured
Header X-Razorpay-Signature, hex encoded HMAC SHA256. Same secret you configured in the dashboard, not the API key.
Conversions API
Header X-Hub-Signature-256 with sha256= prefix. Signed with the App Secret, never the Page or Ad Account token.
Verifications That Fail Silently.
- Signing Parsed JSON. Node Re Serialises With Different Spacing. Always Hold The Raw Bytes.
- Framework Body Parsers. Express And Fastify Consume The Body. Use A Raw Buffer Route.
- Wrong Encoding. Hex Versus Base64. Match The Provider Exactly.
- Case Sensitive Headers. Read Headers Case Insensitively. Cloudflare Lowercases Everything.
- No Idempotency. Providers Retry On 5xx. Dedupe By Event ID In Your Database.
- Before Launch. Prove Your Verification Code Matches The Provider Byte For Byte.
- During Incident Response. Rebuild The Signature Locally And Compare Against The Failing Request.
- Secret Rotation. Test The New Secret Against A Sample Payload Before You Ship It To Production.
- Third Party Debugging. When A Provider Says The Signature Is Wrong, Show Them The Exact Bytes You Signed.
