Skip to content

Webhook signature checker

Check why a webhook "does not validate": verify Meta/WhatsApp, Stripe, GitHub and Telegram signatures with your secret and the raw body.

Our tools run in your browser — nothing you paste or open is uploaded to us or stored by us.

Sender

Meta signs the raw body with your App Secret: X-Hub-Signature-256 = sha256= + hex HMAC-SHA256.

Checked locally with WebCrypto. Prefer a test secret, and rotate any live secret you paste anywhere.

Paste the body exactly as received. Text boxes turn CRLF line endings into LF — load a file if the bytes matter.

0 bytes

Common mistakes

  • Verifying a re-serialised body: JSON.parse then JSON.stringify changes spacing, key order and escapes. Read the raw bytes (e.g. express.raw(), request.body() before parsing).
  • Adding or removing a trailing newline or whitespace when copying, logging or reading the body.
  • Decoding the body with the wrong encoding — non-ASCII text such as Lao must stay UTF-8 bytes.
  • Using the wrong secret: Meta uses the App Secret (not the verify token or access token); Stripe uses the endpoint's whsec_ secret, which differs between test and live mode and between endpoints.
  • Comparing with the wrong header (e.g. the legacy SHA-1 X-Hub-Signature) or forgetting the "sha256=" prefix.
  • Stripe: server clock drift or replaying an old event makes the timestamp check fail even when the signature is right.
  • Telegram: secret_token may only contain A–Z, a–z, 0–9, _ and -, up to 256 characters.
All free tools