dev.workers.bhazarstudio.datoka-hooks-test/datoka-hooks

Datoka Hooks

Public webhook relay with signed observations, retries and verified receivers. Self-service.

0.7.6
Version
remote
Transport
9
Tools

Security review

Review passed

Reviewed Jan 1, 2000.

  • tools: 9 tools scanned
  • metadata: scanned

No findings.

Tools (9)

  • get_hook_credits

    Read remaining purchased admission credits for an existing hook using its management token. Free and read-only; does not purchase credits. Use purchase_hook_credits to request a quote. The daily free allowance remains separate.

  • purchase_hook_credits

    Request an x402 quote without payment, or buy credits with an explicitly authorized signed payment. Reuse purchaseId and the same payment after any timeout.

  • register_destination

    Register an HTTPS receiver you control. Returns hookId, private credentials and the ownership challenge; delivery remains inactive. Publish the exact challenge on your origin, then call verify_destination. Keep recoveryKey secret and reuse it with the identical target after interruption; do not register again with a new key.

  • verify_destination

    Fetch the ownership challenge from the previously registered receiver and activate it when valid. First publish the exact challenge returned by register_destination. Requires the management token; does not deliver an event. Use get_destination_status to inspect progress without activation.

  • get_destination_status

    Read the existing hook ownership challenge and verification or revocation status using its management token. No activation or delivery. Use after registration or an interrupted verification; use get_hook_delivery for one accepted event.

  • revoke_destination

    Permanently revoke this hook with its management token after explicit owner approval. New submissions are rejected; previously accepted deliveries finish. This does not cancel queued events and cannot be undone. Use get_destination_status first if you only need to inspect access.

  • accept_hook_event

    Enqueue up to 65536 payload bytes for a previously verified receiver using its delivery token. Returns a deliveryId, not proof of delivery. Reuse eventId and exact bytes on retries, then poll get_hook_delivery. The free allowance is 100 events/day per verified receiver; extra admissions consume purchased credits. No arbitrary destination can be supplied here.

  • get_hook_delivery

    Read one accepted event by its returned deliveryId and hook delivery token. Poll after accept_hook_event to distinguish queued, retried and completed delivery. Signed observations attest relay attempts, not successful business processing by the receiver. No new delivery or payment.

  • verify_hook_receipt

    Check an unchanged event and signed receipt returned by get_hook_delivery within the authenticated hook. Requires the delivery token; does not send an event. A valid signature attests relay observations, not business truth or exactly-once processing.