Features

HookWatcher captures webhook requests exactly as sent, helps you understand them, delivers them to your application with retries, and tells you when delivery breaks.

Capture

An endpoint is a URL that records every request sent to it. Give it to a provider, a test script or a teammate and requests appear in the workspace as they arrive.

Any method, any sub-path
POST, PUT, PATCH, DELETE, GET and HEAD are captured, including /{endpoint}/any/nested/path.
Exact bytes
Bodies up to 128 KiB are stored unchanged with a SHA-256 fingerprint; compressed and binary bodies are kept as received.
Everything around the body
Headers in original order and case, repeated query parameters, cookies, source IP and receive time.
Your response
Choose the status code, body, headers and an optional delay that senders receive.
Retention
Requests are kept for your plan's retention period and request limit; anonymous endpoints keep 100 requests for 7 days.
Creating endpoints
https://hookwatcher.com/hw8f92k3x7q1m/any/pathsample data
  • POSTpush20008:42:18
  • POSTorders/create20008:42:11
  • POSTpayment.captured20008:41:57
  • GET/health-check20008:41:40

Inspect

Each request opens in an inspector built for webhook payloads, so you can answer what was sent before you open your server logs.

JSON tree
Collapse, search and copy a path such as data.items[0].price or a single value.
Headers and query
Credential headers are masked until you reveal them; masking never changes the stored request.
Raw view
The request line, headers and body as one HTTP message, plus a hex view for binary bodies.
Provider detection
Stripe, GitHub, Shopify, Twilio, Razorpay, PayPal, Slack, Discord, WooCommerce and Paddle requests are labelled with their event type.
Signature verification
Stripe and GitHub signatures are checked against the captured bytes with your signing secret (paid plans).
Copy as code
Copy any request as cURL, Node.js or Python to reproduce it locally.
Inspecting requests
hookwatcher.com · Stripe production · payment.completedsample data
POSTpayment.completedStripeSignature verified
{
"event": "payment.completed",
"id": "evt_8K2QF",
"data": {
"payment_id": "pay_3821",
"amount": 1499,
"currency": "USD",
"customer": {
"id": "cus_829"
}
}
}

Forward

Forwarding relays each captured request to your own server, so HookWatcher can sit permanently between a provider and your application.

Exact or wildcard destinations
Send everything to one URL, or end the destination in /* to append the incoming sub-path.
Query merge
Destination query parameters win; incoming parameters with other names are appended in order.
Header policy
Content, signature, provider and custom headers are forwarded; hop-by-hop and proxy headers are dropped; credentials only when you allow it.
Identification headers
X-HookWatcher-Request-Id, -Hook-Id, -Received-At and -Forward-Attempt let your server deduplicate.
Success rule
Any 2xx response is delivered. Other statuses, timeouts and redirects are failed attempts; redirects are never followed.
Availability
Included with a free account (100 deliveries a day) and higher limits on paid plans.
Forwarding guide
Received
POST /hw8f92k3x7q1m/orders/123?source=app
Forwarded to
https://api.example.com/webhooks/orders/123?source=app
Result
200 OK · 178 ms

destination: https://api.example.com/webhooks/*

Replay & compare

Send a captured request again whenever you need to — to your forwarding destination or to another URL — and compare two requests field by field.

Send again
Re-deliver a stored request to the forwarding destination immediately, with its own attempt record.
Replay
Resend the original request to any public URL and see the response; edit the body, headers or query first on paid plans.
Compare
Structural and value differences between two requests across body, headers and query (paid plans).
Original stays intact
Edits create a new attempt; the captured request is never modified.
Manual retry and replay
evt_7Q1… → evt_8K2Q…+ added− removed~ changed: 1
"id": "evt_8K2QF",
removed: "status": "pending",
added: "status": "completed",
"amount": 1499,
removed: "legacy_ref": "ord_771",
added: "refunded_at": null,

Monitor

HookWatcher shows whether delivery is working, not just what arrived.

Delivery state
Every request shows Queued, Forwarding, Retrying, Delivered or Failed, updated live.
Attempt history
Status, response headers, the first 8 KiB of the response body, latency and failure type for every attempt.
Automatic retries
Three attempts in total, about 10 seconds and 45 seconds apart.
Failure email
Requests that fail every automatic attempt are summarised in at most one email per hour; you can opt out.
Schema changes
Each event type's field structure is recorded; added, removed and retyped fields are flagged.
Analytics
Request volume, status codes, providers and response times per endpoint.
Retries and alerts
Delivery attemptsDelivered
Sent
08:43:10 · after 45 s
Response
200 OK · 172 ms
Destination
https://api.example.com/webhooks/stripe
{"received":true}

Forwarding failures

3 requests failed after all automatic attempts in the last hour

  • POSTcheckout.completed503
  • POSTinvoice.createdTimeout
  • POSTpayment.failed502

At most one email per hour. Each request can be sent again from its page.

Schema changedcustomer.updated
Removed
customer.email
Added
customer.contact.email
Retyped
amount string → number

Secure

Webhook payloads often carry customer and payment data. The defaults assume that.

Private by default
Endpoints you create are visible to you and the people you share them with, unless you make one public.
Destination rules
Forwarding and replay refuse localhost, private networks and cloud metadata addresses; DNS is checked on every delivery and the checked address is used for the connection.
Limits
128 KiB requests, 64 KiB response reads, delivery timeouts and per-day quotas.
Secrets
Signing secrets are encrypted at rest and never displayed again; API keys are stored as hashes and can be scoped and revoked.
Account security
Authenticator-app two-factor authentication and password reset.
Security
  • https://api.example.com/hooks

    Allowed. DNS is checked again on every delivery.

  • http://localhost:3000/webhooks

    Localhost and private network destinations cannot be used for webhook forwarding.

  • http://192.168.1.10/hooks

    Private or local network destinations are not allowed.

  • http://169.254.169.254/latest/meta-data

    Private or local network destinations are not allowed.

Document & build

Turn what you captured into something your team can use.

Generated documentation
Create documentation for a request from its real payload and share it with a link (uses AI credits on paid plans).
Provider setup notes
Endpoint templates with setup steps for common providers (paid plans).
Export
Download request history for offline analysis on registered plans.
API
Scoped API keys and a REST API for endpoints and requests, managed on the developer page.
API reference

Use cases

Payment webhooks
Check that a payment.succeeded event carries the amount and metadata you expect, verify the signature, and replay it against staging.
E-commerce events
Watch order and fulfilment webhooks from Shopify or WooCommerce arrive in sequence and compare two orders that behaved differently.
Git provider webhooks
Inspect push and pull-request payloads from GitHub before writing a CI hook, with the event type labelled.
Staging integrations
Forward a provider's test traffic to a staging API while keeping every request for later comparison.
Failed deliveries
When your handler starts failing, see the response it returned, fix it, and send the failed requests again.

See it with your own requests.

Create a webhook endpoint