Webhook Toolkit

Webhook URLs for AI agents: receive, wait for, replay, sign and verify webhooks (Stripe, GitHub…).

Should I use this

Quality & Safety

A
Description quality
97%
Schema completeness
82%
Naming quality
94%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (1)

  • LOWTool 'get_webhook_request' description lacks action verbin get_webhook_request

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~1,474Tokens (tool definitions)
~988 BTypical response size
Moderate attention impact (1.15% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "webhook-toolkit": {
      "command": "npx",
      "args": [
        "webhook-toolkit"
      ]
    }
  }
}

Runnable packages

npmwebhook-toolkit0.1.1stdio

Remote endpoints

https://webhook-toolkit.com/mcpstreamable-http

What it can do

Tool inventory

Tools (10)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟡create_webhook_url(name)

Create a public HTTPS URL that captures every request sent to it (any method, any sub-path). Use it when you need an endpoint to receive a webhook from a third-party service while building or debugging an integration. Returns the URL to configure in the service and a live inspector link for the human.

Input Schema

{
  "type": "object",
  "properties": {
    "name": {
      "description": "Label, e.g. 'stripe-test'",
      "type": "string",
      "maxLength": 60
    }
  },
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢list_webhook_urls

List the webhook URLs of the account behind the API key (requires an API key).

Input Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢wait_for_webhook(token, timeout_seconds, after)

Block until the next request reaches a webhook URL (or the timeout elapses), then return it in full: method, path, headers, body, detected provider and event. Use right after triggering an action that should send a webhook. Call again with `after` set to the last request's createdAt to wait for the following one.

Input Schema

{
  "type": "object",
  "properties": {
    "token": {
      "type": "string",
      "description": "Token of the webhook URL (the part after /r/)"
    },
    "timeout_seconds": {
      "description": "Default 30, max 50",
      "type": "integer",
      "minimum": 1,
      "maximum": 50
    },
    "after": {
      "description": "ISO timestamp: only requests strictly newer than this. Default: now.",
      "type": "string"
    }
  },
  "required": [
    "token"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢list_webhook_requests(token, limit)

List the most recent requests captured by a webhook URL, newest first (summaries; use get_webhook_request for one full request).

Input Schema

{
  "type": "object",
  "properties": {
    "token": {
      "type": "string"
    },
    "limit": {
      "description": "Default 10",
      "type": "integer",
      "minimum": 1,
      "maximum": 50
    }
  },
  "required": [
    "token"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢get_webhook_request(token, request_id)

Return one captured request in full (headers, raw body, detected provider/event).

Input Schema

{
  "type": "object",
  "properties": {
    "token": {
      "type": "string"
    },
    "request_id": {
      "type": "string"
    }
  },
  "required": [
    "token",
    "request_id"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡set_webhook_response(token, status, body, content_type)

Choose what the webhook URL answers to callers (status code, body, content type) — e.g. return 500 to test the sender's retries, or a specific JSON/XML body the service expects.

Input Schema

{
  "type": "object",
  "properties": {
    "token": {
      "type": "string"
    },
    "status": {
      "type": "integer",
      "minimum": 100,
      "maximum": 599
    },
    "body": {
      "type": "string",
      "maxLength": 10000
    },
    "content_type": {
      "type": "string",
      "maxLength": 120
    }
  },
  "required": [
    "token"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡replay_webhook_request(token, request_id, target_url)

Re-send a captured request (same method, headers and raw body) to a PUBLIC URL and return the target's response. Localhost and private IPs are refused here: for localhost use the CLI (`npx webhook-toolkit replay`) or the local MCP server (`npx webhook-toolkit mcp`).

Input Schema

{
  "type": "object",
  "properties": {
    "token": {
      "type": "string"
    },
    "request_id": {
      "type": "string"
    },
    "target_url": {
      "type": "string",
      "format": "uri"
    }
  },
  "required": [
    "token",
    "request_id",
    "target_url"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡sign_webhook_payload(provider, secret, payload, event_type, target_url)

Build a webhook body with a VALID signature header for a provider, to test a handler's signature verification without triggering a real event. Providers: stripe, github, shopify, slack, twilio, mailgun. Returns the headers, the exact body to send and a ready-to-run curl command.

Input Schema

{
  "type": "object",
  "properties": {
    "provider": {
      "type": "string",
      "enum": [
        "stripe",
        "github",
        "shopify",
        "slack",
        "twilio",
        "mailgun"
      ]
    },
    "secret": {
      "type": "string",
      "description": "The webhook signing secret configured in your handler (whsec_… for Stripe)"
    },
    "payload": {
      "description": "JSON payload (or form fields as JSON for Twilio). Default: a realistic sample event.",
      "type": "string"
    },
    "event_type": {
      "description": "Sample event to use when no payload is given, e.g. checkout.session.completed",
      "type": "string"
    },
    "target_url": {
      "description": "Handler URL (required for Twilio, whose signature covers the URL)",
      "type": "string"
    }
  },
  "required": [
    "provider",
    "secret"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢verify_webhook_signature(provider, secret, raw_body, signature, timestamp, ...)

Check whether a webhook signature is valid for a raw body and a secret, and diagnose why it fails (wrong secret, whitespace, re-serialized JSON body, expired timestamp, wrong URL for Twilio). Providers: stripe, github, shopify, slack, twilio.

Input Schema

{
  "type": "object",
  "properties": {
    "provider": {
      "type": "string",
      "enum": [
        "stripe",
        "github",
        "shopify",
        "slack",
        "twilio"
      ]
    },
    "secret": {
      "type": "string"
    },
    "raw_body": {
      "type": "string",
      "description": "The raw request body exactly as received"
    },
    "signature": {
      "type": "string",
      "description": "The signature header value (Stripe-Signature, X-Hub-Signature-256, X-Shopify-Hmac-Sha256, X-Slack-Signature, X-Twilio-Signature)"
    },
    "timestamp": {
      "description": "Slack only: X-Slack-Request-Timestamp",
      "type": "string"
    },
    "url": {
      "description": "Twilio only: the full URL Twilio called",
      "type": "string"
    }
  },
  "required": [
    "provider",
    "secret",
    "raw_body",
    "signature"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢explain_webhook_request(token, request_id, mode, language)

AI analysis of a captured request. mode=explain: who sent it, which event, key fields, how to verify the signature, pitfalls. mode=handler: complete receiving code that verifies the signature and handles this event. Included in paid plans; anonymous and free users get 3 trials.

Input Schema

{
  "type": "object",
  "properties": {
    "token": {
      "type": "string"
    },
    "request_id": {
      "type": "string"
    },
    "mode": {
      "type": "string",
      "enum": [
        "explain",
        "handler"
      ]
    },
    "language": {
      "description": "Handler language (mode=handler). Default node.",
      "type": "string",
      "enum": [
        "node",
        "nextjs",
        "python",
        "php",
        "go",
        "ruby"
      ]
    }
  },
  "required": [
    "token",
    "request_id"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded10 tools
verifiedversion not recorded10 tools