Signature debugger
Enter the method, path, timestamp, nonce, body and secret you used, and the debugger shows the body hash, the string to sign and the X-Signature step by step, plus the matching headers and a curl command. Paste the signature your code produced into the "compare" field to see whether they match.
The "Webhook signature" tab verifies a webhook you received: enter the webhook secret, the X-Elite-Signature header and the raw body.
How to compare
- Make your code print (or log) the string to sign: five lines joined with
\n. Never log the secret. - Enter the same method, path and query, timestamp, nonce and body above.
- Compare the string to sign in ② line by line. The usual differences are a path missing
/api/tenant/v1, a query string with different encoding or order, or a body that was re-serialized (extra spaces, different field order). - A different body hash in ① means the signed body and the sent body are not the same bytes.
The algorithm and samples in each language are in Authentication & signing.