Webhook Toolkit
Webhook URLs for AI agents: receive, wait for, replay, sign and verify webhooks (Stripe, GitHub…).
Should I use this
Quality & Safety
Findings (1)
- LOWin get_webhook_request
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"webhook-toolkit": {
"command": "npx",
"args": [
"webhook-toolkit"
]
}
}
}Runnable packages
0.1.1stdioRemote endpoints
https://webhook-toolkit.com/mcpstreamable-httpWhat it can do
Tool inventory
Tools (10)
🟡create_webhook_url(name)
Create a public HTTPS URL that captures every request sent to it (any method, any sub-path). Use it when you need an endpoint to receive a webhook from a third-party service while building or debugging an integration. Returns the URL to configure in the service and a live inspector link for the human.
Input Schema
{
"type": "object",
"properties": {
"name": {
"description": "Label, e.g. 'stripe-test'",
"type": "string",
"maxLength": 60
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢list_webhook_urls
List the webhook URLs of the account behind the API key (requires an API key).
Input Schema
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢wait_for_webhook(token, timeout_seconds, after)
Block until the next request reaches a webhook URL (or the timeout elapses), then return it in full: method, path, headers, body, detected provider and event. Use right after triggering an action that should send a webhook. Call again with `after` set to the last request's createdAt to wait for the following one.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string",
"description": "Token of the webhook URL (the part after /r/)"
},
"timeout_seconds": {
"description": "Default 30, max 50",
"type": "integer",
"minimum": 1,
"maximum": 50
},
"after": {
"description": "ISO timestamp: only requests strictly newer than this. Default: now.",
"type": "string"
}
},
"required": [
"token"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢list_webhook_requests(token, limit)
List the most recent requests captured by a webhook URL, newest first (summaries; use get_webhook_request for one full request).
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string"
},
"limit": {
"description": "Default 10",
"type": "integer",
"minimum": 1,
"maximum": 50
}
},
"required": [
"token"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢get_webhook_request(token, request_id)
Return one captured request in full (headers, raw body, detected provider/event).
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string"
},
"request_id": {
"type": "string"
}
},
"required": [
"token",
"request_id"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡set_webhook_response(token, status, body, content_type)
Choose what the webhook URL answers to callers (status code, body, content type) — e.g. return 500 to test the sender's retries, or a specific JSON/XML body the service expects.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string"
},
"status": {
"type": "integer",
"minimum": 100,
"maximum": 599
},
"body": {
"type": "string",
"maxLength": 10000
},
"content_type": {
"type": "string",
"maxLength": 120
}
},
"required": [
"token"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡replay_webhook_request(token, request_id, target_url)
Re-send a captured request (same method, headers and raw body) to a PUBLIC URL and return the target's response. Localhost and private IPs are refused here: for localhost use the CLI (`npx webhook-toolkit replay`) or the local MCP server (`npx webhook-toolkit mcp`).
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string"
},
"request_id": {
"type": "string"
},
"target_url": {
"type": "string",
"format": "uri"
}
},
"required": [
"token",
"request_id",
"target_url"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡sign_webhook_payload(provider, secret, payload, event_type, target_url)
Build a webhook body with a VALID signature header for a provider, to test a handler's signature verification without triggering a real event. Providers: stripe, github, shopify, slack, twilio, mailgun. Returns the headers, the exact body to send and a ready-to-run curl command.
Input Schema
{
"type": "object",
"properties": {
"provider": {
"type": "string",
"enum": [
"stripe",
"github",
"shopify",
"slack",
"twilio",
"mailgun"
]
},
"secret": {
"type": "string",
"description": "The webhook signing secret configured in your handler (whsec_… for Stripe)"
},
"payload": {
"description": "JSON payload (or form fields as JSON for Twilio). Default: a realistic sample event.",
"type": "string"
},
"event_type": {
"description": "Sample event to use when no payload is given, e.g. checkout.session.completed",
"type": "string"
},
"target_url": {
"description": "Handler URL (required for Twilio, whose signature covers the URL)",
"type": "string"
}
},
"required": [
"provider",
"secret"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢verify_webhook_signature(provider, secret, raw_body, signature, timestamp, ...)
Check whether a webhook signature is valid for a raw body and a secret, and diagnose why it fails (wrong secret, whitespace, re-serialized JSON body, expired timestamp, wrong URL for Twilio). Providers: stripe, github, shopify, slack, twilio.
Input Schema
{
"type": "object",
"properties": {
"provider": {
"type": "string",
"enum": [
"stripe",
"github",
"shopify",
"slack",
"twilio"
]
},
"secret": {
"type": "string"
},
"raw_body": {
"type": "string",
"description": "The raw request body exactly as received"
},
"signature": {
"type": "string",
"description": "The signature header value (Stripe-Signature, X-Hub-Signature-256, X-Shopify-Hmac-Sha256, X-Slack-Signature, X-Twilio-Signature)"
},
"timestamp": {
"description": "Slack only: X-Slack-Request-Timestamp",
"type": "string"
},
"url": {
"description": "Twilio only: the full URL Twilio called",
"type": "string"
}
},
"required": [
"provider",
"secret",
"raw_body",
"signature"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢explain_webhook_request(token, request_id, mode, language)
AI analysis of a captured request. mode=explain: who sent it, which event, key fields, how to verify the signature, pitfalls. mode=handler: complete receiving code that verifies the signature and handles this event. Included in paid plans; anonymous and free users get 3 trials.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string"
},
"request_id": {
"type": "string"
},
"mode": {
"type": "string",
"enum": [
"explain",
"handler"
]
},
"language": {
"description": "Handler language (mode=handler). Default node.",
"type": "string",
"enum": [
"node",
"nextjs",
"python",
"php",
"go",
"ruby"
]
}
},
"required": [
"token",
"request_id"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}Community
Evidence