UUID Studio

API Signature Tester

HMAC signatures for webhooks & APIs.

  • đź”’ No data stored or uploaded
  • ⚡ 100% client-side
  • 🆓 Free, no account
Click Convert when ready

Override only when Auto cannot parse your paste. Changing this loads a matching sample into Input — click Convert to run. Use Load sample to cycle every format example.

All conversions

Read-only representations of the same 16 bytes. Every textual form is listed here, not in “Prefer format”.

Paste two values: if both sides are valid JSON, a structural diff appears; otherwise UUID / bytes are compared when both decode to the same format.

A
B

Create or edit JSON here (syntax colors), then format, validate, or convert - same as MongoDB $binary UUID blobs on the Convert tab once detected.

New document

Hash, HMAC, AES-GCM/CBC + RSA-OAEP, codecs, JWT decoding, UUID v4, and secure random - all client-side. JWTs use Base64URL (three segments), not a single MIME Base64 block - use Decode JWT below, not raw Base64 decode.

About API Signature Tester

GitHub, Stripe, and most webhook providers sign their payloads with HMAC so you can verify a request actually came from them and wasn't tampered with in transit - but reproducing that signature by hand while debugging an integration is fiddly.

Compute HMAC-SHA256, SHA-384, or SHA-512 signatures over a request body with your shared secret, in hex or Base64, and compare against what your webhook handler received - a fast way to isolate whether a signature mismatch is your code's fault or a config issue.