JSON HMAC Verifier
Generate and verify HMAC signatures for JSON webhook payloads. Supports SHA-256, SHA-512, and other algorithms.
Features
đ HMAC Generation
- SHA-256, SHA-512, SHA-1 support
- Outputs hex and Base64 formats
- Auto-normalizes JSON before signing
- Uses Web Crypto API (no server needed)
â Signature Verification
- Paste expected signature to verify
- Supports hex and Base64 comparison
- Handles GitHub/Stripe-style prefixes
- Clear pass/fail status indicator
đ Privacy First
- All computation runs in-browser
- Secrets never leave your device
- No server-side processing
- Safe for sensitive webhook secrets
HMAC Webhook Guide
What is HMAC?
HMAC (Hash-based Message Authentication Code) is a mechanism for verifying the integrity and authenticity of a message using a shared secret key. Webhook providers use it to prove that a payload genuinely came from them.
# Node.js example
const crypto = require('crypto');
const secret = 'my-webhook-secret';
const payload = JSON.stringify(body);
const sig = crypto.createHmac('sha256', secret).update(payload).digest('hex');
// GitHub sends: X-Hub-Signature-256: sha256=<sig>
Webhook verification checklist
Most failed webhook verifications come down to the exact bytes being signed. Providers sign the raw request body, so anything that changes those bytes, even reformatting, produces a different signature.
Tips and common pitfalls
- Verify against the raw body before parsing it. In Express, use
express.raw()for the webhook route instead ofexpress.json(). - Check how the provider encodes the signature (hex or Base64) and whether it adds a prefix such as
sha256=. - Some providers sign a timestamp together with the body. Include it exactly as documented and reject old timestamps to block replay attacks.
- Compare signatures with a constant-time function such as
crypto.timingSafeEqualorhmac.compare_digest.
More questions
Where is the signature sent?
In an HTTP header whose name depends on the provider, for example Stripe-Signature, X-Hub-Signature-256 for GitHub or X-Shopify-Hmac-Sha256.
Should I paste production secrets here?
Calculations run locally in your browser, but as a habit use a test or rotated secret when debugging in any web tool.