Utilo

HTTP Signature Calculator

Compute and debug API request signatures step by step: AWS Signature V4, Alibaba Cloud ACS3, Tencent Cloud TC3-HMAC-SHA256 and OAuth 1.0a, and verify GitHub, Stripe and Slack webhook signatures — locally with Web Crypto.

What this HTTP signature calculator does

"The request signature we calculated does not match the signature you provided" is one of the most frustrating errors in API work, because the server never tells you which step went wrong. This calculator reproduces the whole signing process for AWS Signature Version 4, Alibaba Cloud ACS3-HMAC-SHA256, Tencent Cloud TC3-HMAC-SHA256 and OAuth 1.0a HMAC-SHA1, and shows every intermediate value: the canonical request, its hash, the string to sign, the derived signing key and the final signature and headers. It also verifies incoming webhook signatures from GitHub, Stripe and Slack. All cryptography uses the browser's Web Crypto API, so your secret keys stay on your device.

How to use it

  1. Pick the provider tab.
  2. Enter the method, URL, headers (one Name: value per line) and body exactly as your code sends them.
  3. Enter the access key, secret key and, where relevant, region and service. Click Use current time or pin a fixed timestamp to compare with a captured request.
  4. Compare each step with what your SDK or code logs. The first step that differs is where your bug is.
  5. For webhooks, paste the raw request body byte-for-byte, the signature header and your signing secret, and the tool tells you whether it matches.

Common causes of signature mismatches

  • Canonical URI encoding: AWS encodes each path segment; S3 does not double-encode.
  • Query ordering: parameters must be sorted by encoded key, and empty values still need =.
  • Signed headers: header names are lowercased, trimmed, sorted and joined with ;. Forgetting host or x-amz-date is common.
  • Payload hash: S3 requires the x-amz-content-sha256 header; other services just hash the body.
  • Clock skew: most providers reject requests more than 5–15 minutes off.
  • Webhooks: frameworks often parse and re-serialize JSON before you see it. Verify against the raw bytes, not a re-encoded object. Stripe signs timestamp.body, Slack signs v0:timestamp:body.

Frequently asked questions

Is it safe to enter my secret key?

The page performs all calculations locally with Web Crypto and sends nothing. For production secrets, prefer temporary credentials or a test key anyway.

Has the AWS implementation been tested?

Yes. It reproduces the example signatures from the AWS Signature Version 4 documentation, which are part of the site's automated tests.

Does it support AWS SigV4A or presigned URLs?

Not yet. Header-based SigV4 is supported; presigned query-string signing is on the roadmap.

Why does OAuth 1.0a need my body parameters?

For form-encoded bodies, the parameters are part of the signature base string. JSON bodies are not included.

Yes. All processing happens directly in your browser using JavaScript, Web Workers and Web APIs. Nothing you type, paste or upload is sent to our servers.