Replay sends a captured webhook again: same method, path, query, headers and raw body. Nothing is reformatted and no headers are added, so your server sees what the provider originally sent.
hwcli replay evt_93df18ab # to your hwcli listen target hwcli replay evt_93df18ab --target :8080/webhooks # or any local URL
Replaying evt_93df18ab Event: invoice.paid Target: http://localhost:8080/webhooks Response: 200 OK Time: 42 ms
Event IDs work in full, as evt_ plus the first 8 characters, or as any unique prefix. When a prefix matches events in more than one endpoint, add --hook.
From the dashboard
- Replay Locally sends the event to an hwcli session that is listening. Pick the device when several are online.
- Replay to URL sends it from HookWatcher's servers to a public URL such as a staging server. Private and internal addresses are blocked.
- Modify & Replay changes fields first. See Modify and replay.
The original never changes
Each replay is a new record linked to the original event, with its own request, response, status, time, target and the person or CLI session that sent it. The captured bytes are never modified, so you can always go back to exactly what the provider sent.
Signatures and timestamps
Exact replays keep the original signature. That works for providers that sign only the body, such as GitHub and Shopify. Stripe signs a timestamp too, and rejects signatures older than five minutes by default. For those, add --resign to sign the request with your endpoint's stored signing secret. See Testing signature validation.
Production safety
Replays to hosts that look like production (no staging, dev, test or localhost in the name) ask for confirmation. Workspace admins can turn production replays off entirely in Workspace settings → Debugging. In CI, --yes confirms without asking.