Webhook signature verifier
Check an HMAC webhook signature for GitHub, Stripe, Slack or Shopify — and when it fails, find out which near-miss of your payload the sender actually signed.
Scheme
X-Hub-Signature-256 — HMAC-SHA256 over the raw request body. The header carries a sha256= prefix.
Computed with your browser's Web Crypto implementation. When verification fails, the signature is recomputed over the near-miss variants — trailing newline, trimmed body, re-serialised JSON, converted line endings, trimmed secret, other encoding — and the one that matches names the actual bug. Re-serialised JSON is the usual answer, and the hardest to see, because the object is identical and only the bytes differ. Your secret never leaves the page.
Other tools
- EDI viewer & validator (X12 + EDIFACT)
- X.509 certificate decoder
- JSON ↔ XML converter
- CSV ↔ JSON converter
- OpenAPI linter
- MCP tool-definition linter
- OpenAPI → agent tools
- Agent blast-radius calculator
- Prompt secret scanner
- Agent cost & context calculator
- Agent-readiness scorecard
- iPaaS readiness assessment
- Modernisation roadmap generator
- Migration risk register
- Cutover runbook builder
- Interface catalogue builder
- Migration wave planner
- Function Point estimator
- Platform migration assessor
- Fixed-width flat file parser
- webMethods flow reader
- SAP IDoc viewer
- SWIFT MT & ISO 20022 viewer
- HL7 v2 message viewer
- XSLT tester
- XPath tester
- CI/CD workflow security linter
- Regex tester & ReDoS checker
- SLA & error budget calculator
- Retry & backoff simulator
- JSONPath tester
- JSON Schema generator
- Encoding & mojibake fixer
- JSON formatter & validator
- JSON diff
- Epoch & timestamp converter
- Base64 encoder & decoder
- UUID & ULID generator
- JWT decoder
- Cron expression explainer
- Interface math calculator
- Post-quantum migration matrix
- Post-quantum exposure calculator
These exist because the underlying problem is real. If the numbers you just put in look uncomfortable, that is usually worth a conversation.

