← All tools

X-Hub-Signature-256 verifier and generator

Meta signs every webhook with X-Hub-Signature-256: sha256=<hex> — an HMAC-SHA256 of the raw request body, keyed with your app secret. Paste a body and secret below to check a signature, or leave the signature empty to generate one.

Your secret and body never leave this tab: the HMAC is computed locally with the Web Crypto API. View source if you would rather check than trust us.

When a valid signature still fails

Almost every report of “Meta's signature is wrong” comes down to one of three things. A re-serialised body: hashing JSON.stringify(req.body) instead of the bytes that arrived changes key order and whitespace, so the digest changes too — capture the raw body before any JSON middleware. The wrong key: the HMAC key is the app secret from App Dashboard → Settings → Basic, not the verify token, which is only used once for the hub.challenge handshake. A non-constant-time compare: that one still passes here, but leaks timing in production — use crypto.timingSafeEqual.

The long version, with working Node code, is in our signature guide.

Relayo does this part for you: one callback URL, verified on arrival, fanned out to every tool you run — with retries and one-click replay.

See how Relayo works