APIs & Agentic AI
Webhook signature verifier
Check an HMAC webhook signature for GitHub, Stripe, Slack or Shopify — and when it fails, find out which near-miss of your payload the sender actually signed.
Scheme
X-Hub-Signature-256 — HMAC-SHA256 over the raw request body. The header carries a sha256= prefix.
Computed with your browser's Web Crypto implementation. When verification fails, the signature is recomputed over the near-miss variants — trailing newline, trimmed body, re-serialised JSON, converted line endings, trimmed secret, other encoding — and the one that matches names the actual bug. Re-serialised JSON is the usual answer, and the hardest to see, because the object is identical and only the bytes differ. Your secret never leaves the page.
More in this category
These exist because the underlying problem is real. If the numbers you just put in look uncomfortable, that is usually worth a conversation.
Stay ahead of the integration layer.
Integronauts Signal — practical enterprise integration, API and agentic AI thinking. The tools stay free either way.
Integronauts Signal is launching soon.
Practical enterprise integration, APIs, agentic AI and emerging architecture. Sign-up opens when the list does — nothing to enter yet.

