Webhook signature checker
Check why a webhook "does not validate": verify Meta/WhatsApp, Stripe, GitHub and Telegram signatures with your secret and the raw body.
Our tools run in your browser — nothing you paste or open is uploaded to us or stored by us.
Common mistakes
- Verifying a re-serialised body: JSON.parse then JSON.stringify changes spacing, key order and escapes. Read the raw bytes (e.g. express.raw(), request.body() before parsing).
- Adding or removing a trailing newline or whitespace when copying, logging or reading the body.
- Decoding the body with the wrong encoding — non-ASCII text such as Lao must stay UTF-8 bytes.
- Using the wrong secret: Meta uses the App Secret (not the verify token or access token); Stripe uses the endpoint's whsec_ secret, which differs between test and live mode and between endpoints.
- Comparing with the wrong header (e.g. the legacy SHA-1 X-Hub-Signature) or forgetting the "sha256=" prefix.
- Stripe: server clock drift or replaying an old event makes the timestamp check fail even when the signature is right.
- Telegram: secret_token may only contain A–Z, a–z, 0–9, _ and -, up to 256 characters.