AnyHook
A webhook inbox for agents: one call returns a live URL. Mock, verify, inspect and replay.
- 0.2.4
- Version
- remote + npm
- Transport
- 12
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 12 tools scanned
- metadata: scanned
- packages: 1 checked
No findings.
Tools (12)
anyhook_mock
Generate a webhook request with a valid signature for Stripe, GitHub, or Slack. If targetUrl is provided, the request is POSTed there and the response is returned.
anyhook_verify
Verify a webhook signature against a secret. Supports 20 providers including stripe, github, shopify, slack, line, discord, linear, vercel, paddle, hubspot, and paypal.
anyhook_providers
List webhook providers AnyHook can mock, along with the event types available for each.
anyhook_apps_list
List apps in your AnyHook account with inbound URLs, sources, and destination URLs. Check isActive: an inactive app's inbound URL answers setup handshakes but acknowledges and discards event POSTs (202, reason app_inactive) instead of relaying them. Destination signing secrets are redacted to has_signing_secret plus a 4-char hint; a new secret in plaintext comes only from rotating it. An app whose slug was changed lists its former URLs under legacyInboundUrls; those still route to it.
anyhook_inbox
Every AnyHook app is also an email inbox: mail sent to {user}.{app}@anyhook.net becomes an event (type email.received) you can read with anyhook_events. Returns the address and webhook URL for one of your apps.
anyhook_apps_create
Create a new app with a name, provider source, and (optionally) destinations. Returns the inbound URL. The app is active immediately. Created WITHOUT destinations it still receives and LOGS every event (inspect-only), it just delivers nowhere until a destination is added (PATCH /api/v1/apps/{slug} with {"destinations": [...]}).
anyhook_connect
Wire a provider to AnyHook in one call: give a Stripe or GitHub key and AnyHook registers the app's inbound URL as a webhook at the provider, saves the signing secret it yields, and turns on signature verification at the edge. The provider is read from the key; the key is used once and not stored. Without appSlug a new app is created (and removed again if the provider refuses the key). Re-running replaces the registration instead of duplicating it. GitHub sends a signed ping immediately, so the first event appears within seconds. Add a destination afterwards (PATCH /api/v1/apps/{slug}) to forward events; until then they are received and logged.
anyhook_replay
Re-send a stored event to its destinations. Replays sit outside the monthly event quota but within a daily replay limit per plan, and replaying an event that was held for quota bills it as a new event. The destination does run its handler again: a receiver that is not idempotent will process the event twice while debugging.
anyhook_undelivered
Show events for the given app that have not successfully reached any destination (failed or still retrying).
anyhook_replay_failed
Re-send every failed event for the given app slug. Useful after fixing a downstream bug to recover queued work.
anyhook_events
List webhook events, most recent first: id, app, type, status, attempt, destination status code, latency, timestamp. Summaries only, no request headers or body — call anyhook_inspect with an id from here to read one event's payload. Uses your AnyHook account when connected, otherwise the local in-memory store.
anyhook_inspect
Full detail for one event by id, including the inbound headers and body that anyhook_events omits, plus the destination's response. Payloads can be large and often contain personal data, so fetch one at a time, only when the body is needed. Account or local store.