Webhook HMAC Signature Debugger
Developer & CodeClient-Side Webhook HMAC SimulatorWebCrypto Native
Debug signature validation errors without leaking signing secrets to external servers. Runs 100% in browser RAM.
Signature Verification FAILED
The calculated digest does not match the signature provided in the request headers.
Server-Side Verification Snippets
// Next.js App Router (src/app/api/webhook/route.ts)
import { NextRequest, NextResponse } from 'next/server';
import crypto from 'crypto';
export async function POST(req: NextRequest) {
// CRITICAL: Must read raw text to avoid JSON mutation
const rawBody = await req.text();
const signature = req.headers.get('stripe-signature') || '';
const secret = process.env.WEBHOOK_SECRET!;
// Parse Stripe header: t=...,v1=...
const parts = Object.fromEntries(signature.split(',').map(p => p.split('=')));
const expectedSig = crypto.createHmac('sha256', secret).update(`${parts.t}.${rawBody}`).digest('hex');
const isValid = crypto.timingSafeEqual(Buffer.from(parts.v1 || ''), Buffer.from(expectedSig));
if (!isValid) {
return NextResponse.json({ error: 'Invalid HMAC signature' }, { status: 401 });
}
// Safe to process verified event
const payload = JSON.parse(rawBody);
return NextResponse.json({ received: true });
}Webhook HMAC Signature Debugger
NewVerify and debug HMAC-SHA256 webhook signatures for Stripe, GitHub, Shopify, Slack, Twilio, and Razorpay using local Web Crypto.
How to Use Webhook HMAC Signature Debugger
Follow these simple steps to process your files securely in browser memory.
Select Webhook Provider Preset
Choose Stripe, GitHub, Shopify, Slack, Twilio, Razorpay, or Custom HMAC (SHA-256 / SHA-1 / SHA-512).
Enter Secret, Payload & Received Header
Paste your signing secret, raw request body, and the signature header received from the provider.
Inspect Visual Diff & Copy Verified Middleware
View character-by-character mismatch highlights, or copy plug-and-play middleware code for your backend stack.
Who Is Webhook HMAC Signature Debugger Built For?
Designed for professionals seeking fast, private, and unlimited client-side execution.
- Debugging mysterious webhook verification failures across Stripe, GitHub, Shopify, Slack, Twilio, and Razorpay
- Detecting invisible CRLF (\r\n) vs LF (\n) newline mutations that cause cryptographic mismatches
- Generating production-ready signature verification middleware for Next.js, Express, FastAPI, and Go
Character-by-Character Diff
Pinpoints exact byte discrepancies.
CRLF vs LF Detector
Solves the #1 cause of webhook verification bugs.
Frequently Asked Questions about Webhook HMAC Signature Debugger
Related Developer & Code Tools
JSON Formatter & Validator
Beautify, validate, fix, and explore complex JSON data with error highlights and collapsible views.
Base64 Encoder & Decoder
Encode and decode strings, images, and binary files to and from Base64 with UTF-8 and URL-safe modes.
Cryptographic Hash Generator
Generate SHA-256, SHA-512, MD5, and SHA-1 hashes with instant verification and checksums.