Standard Webhooks / Svix with Hookwatch Webhook Tester
This inbox is set up for any sender that follows the Standard Webhooks specification, with webhook-id, webhook-timestamp and webhook-signature headers, or the svix- versions of the same headers. The Signature tab base64-decodes your whsec_ secret, signs id.timestamp.body with HMAC-SHA256 and compares every v1 value in the header, including during key rotation.
- Copy the inbox URL and add it as an endpoint in the service that sends the webhooks.
- Trigger an event, or press Send a signed test Standard Webhooks event here to see a request signed with the demo secret whsec_aG9va3dhdGNoX2RlbW9fc2VjcmV0.
- Select the request. The Headers tab opens first: confirm all three headers are present and note whether the sender uses webhook-* or svix-* names.
- Open the Signature tab, which detects the scheme, and paste the whsec_ secret. Valid needs one v1 value to match and the timestamp to be within five minutes.
- Use Show the exact signed string to compare the id.timestamp.body your server builds with the one computed here.
What to know
The Standard Webhooks specification, which Svix created and many webhook senders now follow, signs the string {webhook-id}.{webhook-timestamp}.{raw body} with HMAC-SHA256. The secret is distributed as whsec_ plus base64, and the HMAC key is the decoded bytes, not the text. Implementations that pass the whole whsec_ string to their HMAC function as UTF-8 produce a well-formed but wrong digest, which is the single most common bug in hand-written verifiers.
webhook-signature is a space-delimited list of version,signature pairs such as v1,K5oZfzN95Z9UVu1EsfQmfVNQhnkZ2pj9o9NDN/H/pI4=. Senders put more than one value there while rotating secrets, and verification succeeds when any v1 value matches. The specification also defines v1a for asymmetric ed25519 signatures; this tool checks the symmetric v1 values only. Compare in constant time and reject timestamps more than five minutes from your clock to stop replays.
Senders built on Svix send the same three values as svix-id, svix-timestamp and svix-signature; the content is identical, so a verifier only has to read the other header names. The official standardwebhooks libraries (JavaScript, Python, Go, Java, Rust and more) and the svix packages both work. The webhook-id stays the same across retries of one message, so store it and skip ids you have already processed.
Because the timestamp is signed, a request copied from this inbox and replayed to your server a few minutes later will fail verification even though the signature itself is correct. When you debug with Replay or Copy as curl, temporarily widen the tolerance in your local environment only, or trigger a fresh event. The tool shows the signature check and the timestamp check separately, so you can tell which one failed.
Updated · Cosmovex
Questions
What is the difference between svix-* and webhook-* headers?
Only the names. Svix-based senders use svix-id, svix-timestamp and svix-signature; senders that implement the Standard Webhooks specification directly use webhook-id, webhook-timestamp and webhook-signature. The signed content and the algorithm are the same, and the tool reads either set.
Why does my HMAC not match even with the right secret?
Most often the key was used as text. Strip the whsec_ prefix and base64-decode the remainder; those bytes are the HMAC key. Also check that you sign the raw body and join id, timestamp and body with dots.
Why are there several signatures in the header?
During secret rotation the sender signs with both the old and the new secret and lists each as a v1,… value separated by spaces. Accept the request if any one of them matches.
Does this check v1a (ed25519) signatures?
No. The tool verifies the symmetric v1 HMAC-SHA256 signatures, which is what whsec_ secrets produce. Asymmetric v1a signatures need the sender's public key and are not supported here.
Is the secret sent to your server?
No. Decoding the secret and computing the HMAC happen in your browser with WebCrypto. The request is stored on our server so it appears in your inbox; the secret stays in this browser's storage.
The free plan covers everything on this page. Hookwatch Webhook Tester Pro ($5/mo, billed monthly) is described on the Hookwatch Webhook Tester page.