How to use this developer tool
- Enter or paste the exact source text.
- Choose the algorithm parameters and output encoding.
- Run the operation or press Ctrl/Cmd + Enter.
- Copy or download the result and compare it with the consuming system.
HMAC Verifier processes UTF-8 text locally and returns a copy-ready result without a network request. The verifier recomputes an HMAC for the message and secret, decodes the expected tag, and compares equal-length byte arrays without early exit. The page reports the byte length, selected parameters, and output size so that the same operation can be reproduced in code or at the command line.
A valid result means the supplied tag matches the message and key under the selected HMAC hash. It does not establish how securely the secret was stored or transported.
Whitespace, line endings, character normalization, salts, and keys are part of the input. Preserve them exactly when reproducing a result.
Input
signed webhook body
Result
The output panel shows the computed value plus byte and parameter statistics.
The verifier recomputes an HMAC for the message and secret, decodes the expected tag, and compares equal-length byte arrays without early exit. Input stays in memory for the duration of the page session. The displayed processing time is measured in the browser and varies by device.
Browser text input is UTF-8 and the secret is treated as text. Real webhook systems often require the untouched raw request bytes; parsing and re-serializing a body can invalidate a correct signature.
No. The calculation runs in the current browser tab and the page does not upload the entered text.
Yes. Select the same text encoding and output format, then compare the hexadecimal or Base64 value byte for byte.
Cryptographic hash and derivation functions are built to spread a small input change across the resulting bytes.
No. A digest or derived key is not encryption and cannot be decrypted back into its input.
Text is converted to UTF-8 bytes before processing, so visually similar but differently normalized strings may produce different results.
| Stage | Behavior |
|---|---|
| Input | UTF-8 bytes |
| Output | Hex or Base64 |