API Toolkit

Webhook HMAC Signer

All tools

Sign and verify GitHub, Stripe, and Slack webhook signatures locally. - runs entirely in your browser. Free, fast and private.

How it works

Four simple steps

1

Paste webhook body

Add the raw request body exactly as your provider sent it.

2

Enter signing secret

Use your GitHub, Stripe, Slack, or generic HMAC secret.

3

Sign or verify

Compute the signature locally with Web Crypto - nothing is uploaded.

4

Compare headers

Copy the signed header or confirm a pasted signature matches.

Webhook HMAC Signer

About Webhook HMAC Signer

GitHub, Stripe, and Slack each fold secrets, timestamps, and bodies into slightly different HMAC strings. Webhook HMAC Signer builds and verifies those signatures locally so you can debug receivers without pasting signing secrets into a hosted playground.

Pick the provider preset, paste the raw body, set the timestamp when required, and compare the computed header to what your logs captured. Rejecting stale timestamps is part of the real protocol; mirror that skew check in production code.

Pitfall: verifying against a pretty-printed JSON body while the provider signed the exact bytes on the wire. Capture raw bodies in your middleware tests.

For generic HMAC without vendor framing, HMAC Generator is enough. For JWT shared-secret checks, use JWT Verify instead.

Secrets and payloads remain in the browser Web Crypto path. Clear them after a production incident so the key is not left on a shared screen.

Features

Lightning fast

Processes data instantly with no server round-trips.

100% private

Your data never leaves your browser. Nothing is uploaded.

No installation

Works in any modern browser. Nothing to download or install.

Free forever

No limits, no sign-up, no credit card required.

Cross-platform

Works on desktop, tablet and mobile devices.

Dark & light mode

Beautiful in both themes. Your preference is saved.

Keyboard shortcut

Ctrl Enter - Run tool

Use cases

GitHub deliveries

Reproduce X-Hub-Signature-256 style checks offline.

Stripe webhooks

Sign t=…,v1=… style payloads while building handlers.

Slack requests

Verify v0 signatures with timestamp + body locally.

Instructions

How to use this tool

FAQ

Frequently asked questions

See all FAQs

Answers for this tool. For site-wide help, open the FAQ hub.

Webhook HMAC Signer Sign and verify GitHub, Stripe, and Slack webhook signatures locally. It runs entirely in your browser with instant feedback.

No server upload is required for formatting/validation. Clearing the page removes the text from memory.

Validators report problems; formatters beautify valid structure. Severely broken input may need manual fixes first.

Formatters and converters aim to preserve meaning. Always review diffs for mission-critical code before committing.

Paste smaller chunks if the tab slows down. Minifiers and deep validators scale with input size on the CPU you have.

Many tools support Ctrl/⌘+Enter to run and standard copy shortcuts. Check the tool toolbar for Sample / Clear / Download.

When options exist (spaces vs tabs, indent width), set them before copying output into your repo to match project style.

After the page loads, formatting continues offline. CDN libraries need an initial network load.

Bookmark Webhook HMAC Signer, copy output into editors, or chain steps with Recipes.

View more FAQs

Related tools

View all

Webhook Replay Diff Lab

Compare webhook payload timelines, re-check HMAC digests, and spot idempotency gaps locally.

Open

JSONPath Playground

Query JSON with JSONPath and JMESPath-style paths side by side.

Open

GraphQL Studio

Format, validate, and cost-estimate GraphQL documents with cURL export.

Open

OpenAPI Studio

Validate OpenAPI 3 specs, generate types, and diff breaking changes.

Open

Explore 321 free tools

Everything you need as a developer, marketer or creator - in one beautiful place.

Browse all tools