net.anyhook/anyhook

AnyHook

A webhook inbox for agents: one call returns a live URL. Mock, verify, inspect and replay.

0.2.4
Version
remote + npm
Transport
12
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 12 tools scanned
  • metadata: scanned
  • packages: 1 checked

No findings.

Tools (12)

  • anyhook_mock

    Generate a webhook request with a valid signature for Stripe, GitHub, or Slack. If targetUrl is provided, the request is POSTed there and the response is returned.

  • anyhook_verify

    Verify a webhook signature against a secret. Supports 20 providers including stripe, github, shopify, slack, line, discord, linear, vercel, paddle, hubspot, and paypal.

  • anyhook_providers

    List webhook providers AnyHook can mock, along with the event types available for each.

  • anyhook_apps_list

    List apps in your AnyHook account with inbound URLs, sources, and destination URLs. Check isActive: an inactive app's inbound URL answers setup handshakes but acknowledges and discards event POSTs (202, reason app_inactive) instead of relaying them. Destination signing secrets are redacted to has_signing_secret plus a 4-char hint; a new secret in plaintext comes only from rotating it. An app whose slug was changed lists its former URLs under legacyInboundUrls; those still route to it.

  • anyhook_inbox

    Every AnyHook app is also an email inbox: mail sent to {user}.{app}@anyhook.net becomes an event (type email.received) you can read with anyhook_events. Returns the address and webhook URL for one of your apps.

  • anyhook_apps_create

    Create a new app with a name, provider source, and (optionally) destinations. Returns the inbound URL. The app is active immediately. Created WITHOUT destinations it still receives and LOGS every event (inspect-only), it just delivers nowhere until a destination is added (PATCH /api/v1/apps/{slug} with {"destinations": [...]}).

  • anyhook_connect

    Wire a provider to AnyHook in one call: give a Stripe or GitHub key and AnyHook registers the app's inbound URL as a webhook at the provider, saves the signing secret it yields, and turns on signature verification at the edge. The provider is read from the key; the key is used once and not stored. Without appSlug a new app is created (and removed again if the provider refuses the key). Re-running replaces the registration instead of duplicating it. GitHub sends a signed ping immediately, so the first event appears within seconds. Add a destination afterwards (PATCH /api/v1/apps/{slug}) to forward events; until then they are received and logged.

  • anyhook_replay

    Re-send a stored event to its destinations. Replays sit outside the monthly event quota but within a daily replay limit per plan, and replaying an event that was held for quota bills it as a new event. The destination does run its handler again: a receiver that is not idempotent will process the event twice while debugging.

  • anyhook_undelivered

    Show events for the given app that have not successfully reached any destination (failed or still retrying).

  • anyhook_replay_failed

    Re-send every failed event for the given app slug. Useful after fixing a downstream bug to recover queued work.

  • anyhook_events

    List webhook events, most recent first: id, app, type, status, attempt, destination status code, latency, timestamp. Summaries only, no request headers or body — call anyhook_inspect with an id from here to read one event's payload. Uses your AnyHook account when connected, otherwise the local in-memory store.

  • anyhook_inspect

    Full detail for one event by id, including the inbound headers and body that anyhook_events omits, plus the destination's response. Payloads can be large and often contain personal data, so fetch one at a time, only when the body is needed. Account or local store.