io.github.THE-KIPDEV/webhook-toolkit

Webhook Toolkit

Webhook URLs for AI agents: receive, wait for, replay, sign and verify webhooks (Stripe, GitHub…).

0.1.1
Version
remote + npm
Transport
10
Tools

Security review

Review passed

Reviewed Jan 1, 2000.

  • tools: 10 tools scanned
  • metadata: scanned
  • packages: 1 checked

No findings.

Tools (10)

  • create_webhook_url

    Create a public HTTPS URL that captures every request sent to it (any method, any sub-path). Use it when you need an endpoint to receive a webhook from a third-party service while building or debugging an integration. Returns the URL to configure in the service and a live inspector link for the human.

  • list_webhook_urls

    List the webhook URLs of the account behind the API key (requires an API key).

  • wait_for_webhook

    Block until the next request reaches a webhook URL (or the timeout elapses), then return it in full: method, path, headers, body, detected provider and event. Use right after triggering an action that should send a webhook. Call again with `after` set to the last request's createdAt to wait for the following one.

  • list_webhook_requests

    List the most recent requests captured by a webhook URL, newest first (summaries; use get_webhook_request for one full request).

  • get_webhook_request

    Return one captured request in full (headers, raw body, detected provider/event).

  • set_webhook_response

    Choose what the webhook URL answers to callers (status code, body, content type) — e.g. return 500 to test the sender's retries, or a specific JSON/XML body the service expects.

  • replay_webhook_request

    Re-send a captured request (same method, headers and raw body) to a PUBLIC URL and return the target's response. Localhost and private IPs are refused here: for localhost use the CLI (`npx webhook-toolkit replay`) or the local MCP server (`npx webhook-toolkit mcp`).

  • sign_webhook_payload

    Build a webhook body with a VALID signature header for a provider, to test a handler's signature verification without triggering a real event. Providers: stripe, github, shopify, slack, twilio, mailgun. Returns the headers, the exact body to send and a ready-to-run curl command.

  • verify_webhook_signature

    Check whether a webhook signature is valid for a raw body and a secret, and diagnose why it fails (wrong secret, whitespace, re-serialized JSON body, expired timestamp, wrong URL for Twilio). Providers: stripe, github, shopify, slack, twilio.

  • explain_webhook_request

    AI analysis of a captured request. mode=explain: who sent it, which event, key fields, how to verify the signature, pitfalls. mode=handler: complete receiving code that verifies the signature and handles this event. Included in paid plans; anonymous and free users get 3 trials.