JSON HMAC Verifier

Generate and verify HMAC signatures for JSON webhook payloads. Supports SHA-256, SHA-512, and other algorithms.

Input JSON
HMAC Output

Features

🔏 HMAC Generation

  • SHA-256, SHA-512, SHA-1 support
  • Outputs hex and Base64 formats
  • Auto-normalizes JSON before signing
  • Uses Web Crypto API (no server needed)

✅ Signature Verification

  • Paste expected signature to verify
  • Supports hex and Base64 comparison
  • Handles GitHub/Stripe-style prefixes
  • Clear pass/fail status indicator

🔐 Privacy First

  • All computation runs in-browser
  • Secrets never leave your device
  • No server-side processing
  • Safe for sensitive webhook secrets

HMAC Webhook Guide

What is HMAC?

HMAC (Hash-based Message Authentication Code) is a mechanism for verifying the integrity and authenticity of a message using a shared secret key. Webhook providers use it to prove that a payload genuinely came from them.

# Node.js example
const crypto = require('crypto');
const secret = 'my-webhook-secret';
const payload = JSON.stringify(body);
const sig = crypto.createHmac('sha256', secret).update(payload).digest('hex');
// GitHub sends: X-Hub-Signature-256: sha256=<sig>

Webhook verification checklist

Most failed webhook verifications come down to the exact bytes being signed. Providers sign the raw request body, so anything that changes those bytes, even reformatting, produces a different signature.

Tips and common pitfalls

  • Verify against the raw body before parsing it. In Express, use express.raw() for the webhook route instead of express.json().
  • Check how the provider encodes the signature (hex or Base64) and whether it adds a prefix such as sha256=.
  • Some providers sign a timestamp together with the body. Include it exactly as documented and reject old timestamps to block replay attacks.
  • Compare signatures with a constant-time function such as crypto.timingSafeEqual or hmac.compare_digest.

More questions

Where is the signature sent?

In an HTTP header whose name depends on the provider, for example Stripe-Signature, X-Hub-Signature-256 for GitHub or X-Shopify-Hmac-Sha256.

Should I paste production secrets here?

Calculations run locally in your browser, but as a habit use a test or rotated secret when debugging in any web tool.