Webhook tester and signed-event inspector

OpenVibe.Events delivers each event as POST with the body {"event": <envelope>, "seq": <n>} and these headers, signed with your subscription secret:

Verify against the raw bytes, before parsing, with a constant-time comparison. v2 covers the time as well as the body, so a captured delivery cannot be replayed later: refuse it when t is more than 300 seconds from your clock, in either direction, and reject a delivery whose v2 header is missing, does not verify or is stale. The v1 header (X-OpenVibe-Signature, an HMAC of the body alone, which verifies forever) was retired on 2026-09-28: Events no longer sends it. parseDelivery(raw, headers, secret, { requireV2: true }) in openvibe-sdk/events does all of this; verifyDeliveryV2() checks v2 and the window. The tester below checks v2 the same way, says whether the timestamp is inside the window now, and decides as a receiver that requires v2 does.

Verify a delivery

Without JavaScript the form is sent to Services, which computes the HMAC and forgets the secret. With JavaScript it is computed in your browser and nothing is sent.

Generate a sample delivery