Features
Capture
An endpoint is a URL that records every request sent to it. Give it to a provider, a test script or a teammate and requests appear in the workspace as they arrive.
- Any method, any sub-path
- POST, PUT, PATCH, DELETE, GET and HEAD are captured, including /{endpoint}/any/nested/path.
- Exact bytes
- Bodies up to 128 KiB are stored unchanged with a SHA-256 fingerprint; compressed and binary bodies are kept as received.
- Everything around the body
- Headers in original order and case, repeated query parameters, cookies, source IP and receive time.
- Your response
- Choose the status code, body, headers and an optional delay that senders receive.
- Retention
- Requests are kept for your plan's retention period and request limit; anonymous endpoints keep 100 requests for 7 days.
- Creating endpoints
https://hookwatcher.com/hw8f92k3x7q1m/any/pathsample data- POSTpushGitHub20008:42:18
- POSTorders/createShopify20008:42:11
- POSTpayment.capturedRazorpay20008:41:57
- GET/health-check—20008:41:40
Inspect
Each request opens in an inspector built for webhook payloads, so you can answer what was sent before you open your server logs.
- JSON tree
- Collapse, search and copy a path such as data.items[0].price or a single value.
- Headers and query
- Credential headers are masked until you reveal them; masking never changes the stored request.
- Raw view
- The request line, headers and body as one HTTP message, plus a hex view for binary bodies.
- Provider detection
- Stripe, GitHub, Shopify, Twilio, Razorpay, PayPal, Slack, Discord, WooCommerce and Paddle requests are labelled with their event type.
- Signature verification
- Stripe and GitHub signatures are checked against the captured bytes with your signing secret (paid plans).
- Copy as code
- Copy any request as cURL, Node.js or Python to reproduce it locally.
- Inspecting requests
hookwatcher.com · Stripe production · payment.completedsample data{"event": "payment.completed","id": "evt_8K2QF","data": {"payment_id": "pay_3821","amount": 1499,"currency": "USD","customer": {"id": "cus_829"}}}
Forward
Forwarding relays each captured request to your own server, so HookWatcher can sit permanently between a provider and your application.
- Exact or wildcard destinations
- Send everything to one URL, or end the destination in /* to append the incoming sub-path.
- Query merge
- Destination query parameters win; incoming parameters with other names are appended in order.
- Header policy
- Content, signature, provider and custom headers are forwarded; hop-by-hop and proxy headers are dropped; credentials only when you allow it.
- Identification headers
- X-HookWatcher-Request-Id, -Hook-Id, -Received-At and -Forward-Attempt let your server deduplicate.
- Success rule
- Any 2xx response is delivered. Other statuses, timeouts and redirects are failed attempts; redirects are never followed.
- Availability
- Included with a free account (100 deliveries a day) and higher limits on paid plans.
- Forwarding guide
- Received
- POST
/hw8f92k3x7q1m/orders/123?source=app - Forwarded to
https://api.example.com/webhooks/orders/123?source=app- Result
- 200 OK · 178 ms
destination: https://api.example.com/webhooks/*
Replay & compare
Send a captured request again whenever you need to — to your forwarding destination or to another URL — and compare two requests field by field.
- Send again
- Re-deliver a stored request to the forwarding destination immediately, with its own attempt record.
- Replay
- Resend the original request to any public URL and see the response; edit the body, headers or query first on paid plans.
- Compare
- Structural and value differences between two requests across body, headers and query (paid plans).
- Original stays intact
- Edits create a new attempt; the captured request is never modified.
- Manual retry and replay
"id": "evt_8K2QF",removed: "status": "pending",added: "status": "completed","amount": 1499,removed: "legacy_ref": "ord_771",added: "refunded_at": null,
Monitor
HookWatcher shows whether delivery is working, not just what arrived.
- Delivery state
- Every request shows Queued, Forwarding, Retrying, Delivered or Failed, updated live.
- Attempt history
- Status, response headers, the first 8 KiB of the response body, latency and failure type for every attempt.
- Automatic retries
- Three attempts in total, about 10 seconds and 45 seconds apart.
- Failure email
- Requests that fail every automatic attempt are summarised in at most one email per hour; you can opt out.
- Schema changes
- Each event type's field structure is recorded; added, removed and retyped fields are flagged.
- Analytics
- Request volume, status codes, providers and response times per endpoint.
- Retries and alerts
- Sent
- 08:43:10 · after 45 s
- Response
- 200 OK · 172 ms
- Destination
- https://api.example.com/webhooks/stripe
{"received":true}Forwarding failures
3 requests failed after all automatic attempts in the last hour
- POSTcheckout.completed503
- POSTinvoice.createdTimeout
- POSTpayment.failed502
At most one email per hour. Each request can be sent again from its page.
- Removed
- customer.email
- Added
- customer.contact.email
- Retyped
- amount string → number
Secure
Webhook payloads often carry customer and payment data. The defaults assume that.
- Private by default
- Endpoints you create are visible to you and the people you share them with, unless you make one public.
- Destination rules
- Forwarding and replay refuse localhost, private networks and cloud metadata addresses; DNS is checked on every delivery and the checked address is used for the connection.
- Limits
- 128 KiB requests, 64 KiB response reads, delivery timeouts and per-day quotas.
- Secrets
- Signing secrets are encrypted at rest and never displayed again; API keys are stored as hashes and can be scoped and revoked.
- Account security
- Authenticator-app two-factor authentication and password reset.
- Security
https://api.example.com/hooksAllowed. DNS is checked again on every delivery.
http://localhost:3000/webhooksLocalhost and private network destinations cannot be used for webhook forwarding.
http://192.168.1.10/hooksPrivate or local network destinations are not allowed.
http://169.254.169.254/latest/meta-dataPrivate or local network destinations are not allowed.
Document & build
Turn what you captured into something your team can use.
- Generated documentation
- Create documentation for a request from its real payload and share it with a link (uses AI credits on paid plans).
- Provider setup notes
- Endpoint templates with setup steps for common providers (paid plans).
- Export
- Download request history for offline analysis on registered plans.
- API
- Scoped API keys and a REST API for endpoints and requests, managed on the developer page.
- API reference
Use cases
- Payment webhooks
- Check that a payment.succeeded event carries the amount and metadata you expect, verify the signature, and replay it against staging.
- E-commerce events
- Watch order and fulfilment webhooks from Shopify or WooCommerce arrive in sequence and compare two orders that behaved differently.
- Git provider webhooks
- Inspect push and pull-request payloads from GitHub before writing a CI hook, with the event type labelled.
- Staging integrations
- Forward a provider's test traffic to a staging API while keeping every request for later comparison.
- Failed deliveries
- When your handler starts failing, see the response it returned, fix it, and send the failed requests again.
See it with your own requests.
Create a webhook endpoint