stripesig Webhook Signature Debugger API
Live, free, unauthenticated endpoint behind the stripesig wedge: POST /check accepts {provider (stripe|github|slack|shopify), secret, raw_body, headers, tolerance_seconds?}, recomputes the provider's HMAC-SHA256 webhook signature and returns a plain-English reason the received signature did not verify. Rate-limited 60 requests per 60 s per IP with X-RateLimit-* headers. Not described by any served OpenAPI.