A webhook signature check usually fails because your code verifies a different input from the one the provider signed: the body was parsed or changed, or the endpoint uses the wrong secret, header, digest format, or signing recipe. Capture the original request body and verify it with the provider-specific method before parsing or trusting payload fields. A valid signature is not proof that a delivery is fresh or has not already been processed, so handle freshness, duplicates, and idempotent effects separately.
Why webhook signature checks fail
The body changed before verification
Many providers sign the original request bytes or a precisely defined string built from them. Parsing JSON and serializing it again can change whitespace, key order, escaping, Unicode representation, or encoding even when the resulting object looks equivalent. Stripe lists these kinds of body changes as causes of verification failure, and Shopify likewise requires the raw body for manual verification. See Stripe’s signature troubleshooting guide and Shopify’s verification instructions.
Middleware order is therefore part of correctness. For an Express route, preserve the raw request body and verify it before a JSON or form parser handles that route. Stripe warns that placing express.json() before the webhook route can parse the body too early; Shopify’s manual example uses express.raw({ type: '*/*' }). Adapt the pattern to the current provider SDK and framework version rather than assuming one middleware setup works everywhere.
The same boundary applies outside the application. A proxy, API gateway, load balancer, or serverless adapter may alter bytes or headers, or provide a normalized body instead of the original. GitHub advises checking that proxies and load balancers do not modify the payload or headers; Stripe documents preserving a separate raw-body value in an API Gateway mapping. Do not assume the framework is the only place where the input can change.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
The secret or endpoint does not match
Check which endpoint, application, and environment issued the secret. In Stripe, a Dashboard endpoint secret and a Stripe CLI listener secret are different even though both begin with whsec_; a CLI-forwarded development event will not verify with the Dashboard endpoint secret. GitHub notes that its signature header may be absent when no webhook secret is configured. Slack recommends the app signing secret, not its deprecated verification token. Shopify uses the app client secret; after client-secret rotation, Shopify says it can take up to an hour for generated HMACs to use the new secret.
Keep secrets out of logs and diagnostic output. GitHub recommends a high-entropy random webhook secret in its webhook best practices. If rotation is in progress, account for the provider’s documented behavior; do not weaken verification or add an unsigned fallback.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
The header, signed input, or encoding assumption is wrong
“HMAC webhook” is not one universal format. Providers differ in the bytes or string they sign, the digest algorithm, the header, and how the digest is represented. For example, GitHub’s preferred header carries a SHA-256 HMAC as hex with a sha256= prefix, while Shopify’s body HMAC-SHA256 value is base64. Slack signs v0:{timestamp}:{raw body} and sends a hex digest with a v0= prefix. Stripe recommends the SDK’s constructEvent() path with the original body string, Stripe-Signature header, and endpoint secret.
Check the provider’s exact recipe, including key bytes, signed input, algorithm, output encoding, prefix, and timestamp handling. GitHub also documents a legacy SHA-1 value in X-Hub-Signature; its SHA-256 X-Hub-Signature-256 is the preferred header. Use the maintained provider SDK when it fits your runtime, but still supply the original body.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
The comparison is unsafe or permissive
Use a provider SDK or a constant-time HMAC comparison helper. GitHub and Slack both warn against ordinary equality checks. Make sure the expected and received values use the same encoding and prefix convention: comparing hex to base64, or including a prefix on only one side, will fail. Treat missing, malformed, truncated, or incorrectly split signature values as verification failures. Never let a parse error, absent header, or exception silently bypass the check.
Provider-specific verification differences
| Provider | Signed input and signature representation | Common diagnostic | Freshness and duplicate handling |
|---|---|---|---|
| GitHub | HMAC-SHA256 of the payload; X-Hub-Signature-256 uses a hex digest prefixed by sha256=. Verify with the secret token and original payload. |
Check that a secret is configured, the chosen header and algorithm agree, and proxies or load balancers have not changed the payload or headers. | X-GitHub-Delivery identifies a delivery; GitHub says a redelivery retains the same identifier. Use it to recognize a repeated delivery. |
| Shopify | Base64-encoded HMAC-SHA256 of the raw request body, keyed with the app client secret, in X-Shopify-Hmac-SHA256. |
A body parser ran first, the digest was treated as hex rather than base64, or verification used a parsed representation. | Use idempotent processing or persist X-Shopify-Webhook-Id for delivery deduplication. The event ID can correlate deliveries from the same merchant action. Shopify says new-secret HMAC generation after rotation can take up to an hour. |
| Slack | HMAC-SHA256 of v0:{timestamp}:{raw body}, represented as hex with a v0= prefix, using the app signing secret. |
Check raw-body access, timestamp construction, signing secret, header lookup, and comparison method. Header names are case-insensitive, but frameworks may normalize their representation. | Slack’s example rejects requests whose timestamp differs from local time by more than five minutes. Its documentation says the previous client secret remains valid for 24 hours after regeneration unless manually revoked. |
| Stripe | Use Stripe-Signature, the original UTF-8 body string, and the endpoint secret with constructEvent(). |
Check whether a CLI or Dashboard secret is in use, and whether a body parser or infrastructure layer changed the body before verification. | The signature troubleshooting guidance focuses on verification failure. Consult Stripe’s current event and retry documentation when designing duplicate handling. |
These formats are not interchangeable. For current provider-specific details, use GitHub’s validation guide, GitHub’s best practices, Shopify’s verification guide, Slack’s request verification guide, and Stripe’s troubleshooting guide.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Can a valid signature still be replayed or duplicated?
Yes. A valid signature shows that the provider-defined signed input matches a signature made with the expected secret; it does not, by itself, prove that this is a new delivery or that the business action has not already occurred.
- Freshness: Slack includes a timestamp in its signed string and recommends rejecting requests more than five minutes from local time, as in its example. Use a reliable clock and apply the timestamp check before dispatching the event.
- Delivery replay detection: GitHub’s
X-GitHub-Deliverycan identify a delivery, and a redelivery retains that ID. Shopify distinguishes the delivery ID, useful for deduplicating individual deliveries, from the event ID, which can correlate related deliveries. - Idempotent effects: Persist processed delivery IDs where appropriate and make business operations safe to retry. Shopify explicitly recommends idempotent operations or persistent webhook-ID deduplication. Network timeouts and retries can result in repeated delivery.
These controls address different risks: signature verification authenticates the signed input, freshness or delivery tracking limits repeated acceptance where the provider supports it, and idempotency protects the business operation if processing happens more than once.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
A safe debugging sequence
- Identify the provider, endpoint, environment, and library. Confirm the active app or endpoint secret in its authoritative provider location. For Stripe, distinguish a CLI listener secret from a Dashboard endpoint secret.
- Inspect the expected header and format. Confirm the documented header exists and that its algorithm and encoding match your implementation. Never silently switch to an unsigned path.
- Preserve the raw body. Capture it before JSON or form deserialization. For diagnostics, use a byte length and, if useful, a carefully protected hash or sanitized sample; do not expose secrets or sensitive payloads.
- Recheck the provider’s signing recipe. Verify the exact signed base string, key encoding, digest algorithm, output encoding, prefixes, and any timestamp policy.
- Trace transformations across the request path. Check body parsers, API Gateway mappings, serverless adapters, compression or decompression, and proxy header forwarding. Treat every boundary between sender and verifier as a possible mutation point.
- Test the HMAC implementation independently. GitHub publishes a known test secret, the payload
Hello, World!, and its expected signature in its validation guide. A passing vector checks the implementation, not whether your production middleware preserves raw bytes. - Fail closed, then process. Reject missing or malformed signatures. Parse and dispatch only after verification succeeds; then apply the relevant freshness, deduplication, and idempotency controls.
How to keep verification and processing separate
A robust request path has clear stages: preserve the request representation the provider signed; validate the provider-specific signature; apply freshness or duplicate checks; only then parse or use the payload for application work. A failure at any validation stage should stop dispatch. Keep signature validation distinct from business processing so a retry can be recognized without repeating an irreversible effect.
GitHub says a receiver should respond with a 2XX within 10 seconds or GitHub terminates the connection and considers the delivery a failure. That delivery behavior is another reason to make event processing retry-safe; it is not a reason to skip verification or perform unguarded work inline.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




