How to use Webhook Signature Builder & Verifier
Build or verify HMAC webhook signatures over exact local payload text using SHA-256, SHA-384, or SHA-512.
What to provide
Paste the exact raw payload bytes as text. Whitespace and line endings are significant.
Held only in memory for the current run and omitted from presets.
- Paste, type, or drag and drop a supported text file into the input area.
- Place the second value or file in the adjacent panel. Sensitive fields are masked by default.
- Choose the options that match your intended result.
- Select “Run tool” or press Ctrl/Command + Enter, then copy, download, or move the result back into the first input for another pass.
Use “Swap inputs” to reverse the comparison without copying either value.
What the result means
Calculated signature and constant-time verification result when expected output is provided.
Privacy and safety
This utility is loaded as browser code and processes your input only in this tab. OmniCastConverter has no upload endpoint and never stores your content, filenames, tokens, or secrets. Generated markup and code are shown as inert text and are never executed.
Limitations
- Everything is processed in this browser tab. Input, filenames, keys, and output are never uploaded or saved. Providers may sign timestamps, headers, or canonical byte sequences in addition to the body; follow the provider’s exact scheme.
Try the included example
Select “Load example” at any time to restore this tested sample.
{"event":"invoice.paid","id":"evt_local_42"}local-test-secret