X-Hub-Signature-256 verifier and generator
Meta signs every webhook with
X-Hub-Signature-256: sha256=<hex> — an HMAC-SHA256 of the
raw request body, keyed with your app secret. Paste a body and secret below
to check a signature, or leave the signature empty to generate one.
Your secret and body never leave this tab: the HMAC is computed locally with the Web Crypto API. View source if you would rather check than trust us.
When a valid signature still fails
Almost every report of “Meta's signature is wrong” comes down to one of three things.
A re-serialised body: hashing JSON.stringify(req.body) instead
of the bytes that arrived changes key order and whitespace, so the digest changes too —
capture the raw body before any JSON middleware. The wrong key: the HMAC
key is the app secret from App Dashboard → Settings → Basic, not the verify token, which is
only used once for the hub.challenge handshake.
A non-constant-time compare:
that one still passes here, but leaks timing in production — use
crypto.timingSafeEqual.
The long version, with working Node code, is in our signature guide.
Relayo does this part for you: one callback URL, verified on arrival, fanned out to every tool you run — with retries and one-click replay.
See how Relayo works