AnyHook
A webhook inbox for agents: one call returns a live URL. Mock, verify, inspect and replay.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"anyhook": {
"command": "npx",
"args": [
"anyhook-mcp"
]
}
}
}Runnable packages
0.2.4stdioRemote endpoints
https://anyhook.net/mcpstreamable-httpWhat it can do
Tool inventory
Tools (11)
🔴anyhook_mock(provider, event, data, secret, targetUrl)
Generate a webhook request with a valid signature for Stripe, GitHub, or Slack. If targetUrl is provided, the request is POSTed there and the response is returned.
Input Schema
{
"type": "object",
"properties": {
"provider": {
"type": "string",
"enum": [
"stripe",
"github",
"slack"
],
"description": "Webhook provider to simulate."
},
"event": {
"type": "string",
"description": "Event name (e.g. 'payment_intent.succeeded' for Stripe)."
},
"data": {
"type": "object",
"additionalProperties": {},
"description": "Optional fields to deep-merge into the fixture."
},
"secret": {
"type": "string",
"description": "Signing secret. Falls back to a deterministic default per provider."
},
"targetUrl": {
"type": "string",
"format": "uri",
"description": "If set, POST the generated request to this URL and return the response."
}
},
"required": [
"provider",
"event"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢anyhook_verify(provider, headers, body, secret, requestUrl)
Verify a webhook signature against a secret. Supports 20 providers including stripe, github, shopify, slack, line, discord, linear, vercel, paddle, hubspot, and paypal.
Input Schema
{
"type": "object",
"properties": {
"provider": {
"type": "string",
"description": "Provider name (e.g. 'stripe', 'github', 'slack', 'generic')."
},
"headers": {
"type": "object",
"additionalProperties": {
"type": "string"
},
"description": "Request headers as a flat object."
},
"body": {
"type": "string",
"description": "Raw request body."
},
"secret": {
"type": "string",
"description": "Signing secret to verify against."
},
"requestUrl": {
"type": "string",
"format": "uri",
"description": "Original request URL (required for Twilio/HubSpot). Defaults to a placeholder."
}
},
"required": [
"provider",
"headers",
"body",
"secret"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢anyhook_providers
List webhook providers AnyHook can mock, along with the event types available for each.
Input Schema
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢anyhook_apps_list(api_key)
List apps in your AnyHook account with inbound URLs, sources, and destination URLs. Check isActive: an inactive app's inbound URL answers setup handshakes but acknowledges and discards event POSTs (202, reason app_inactive) instead of relaying them. Destination signing secrets are redacted to has_signing_secret plus a 4-char hint; a new secret in plaintext comes only from rotating it. An app whose slug was changed lists its former URLs under legacyInboundUrls; those still route to it.
Input Schema
{
"type": "object",
"properties": {
"api_key": {
"type": "string",
"description": "API key (ahk_live_...) from anyhook_quickstart. Only needed over HTTP when no Authorization header is set; ignored over stdio."
}
},
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢anyhook_inbox(api_key, app)
Every AnyHook app is also an email inbox: mail sent to {user}.{app}@anyhook.net becomes an event (type email.received) you can read with anyhook_events. Returns the address and webhook URL for one of your apps.
Input Schema
{
"type": "object",
"properties": {
"api_key": {
"type": "string",
"description": "API key (ahk_live_...) from anyhook_quickstart. Only needed over HTTP when no Authorization header is set; ignored over stdio."
},
"app": {
"type": "string",
"description": "App slug (from anyhook_apps_list). Defaults to your first app."
}
},
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡anyhook_apps_create(api_key, name, source, destinations)
Create a new app with a name, provider source, and (optionally) destinations. Returns the inbound URL. The app is active immediately. Created WITHOUT destinations it still receives and LOGS every event (inspect-only), it just delivers nowhere until a destination is added (PATCH /api/v1/apps/{slug} with {"destinations": [...]}).
Input Schema
{
"type": "object",
"properties": {
"api_key": {
"type": "string",
"description": "API key (ahk_live_...) from anyhook_quickstart. Only needed over HTTP when no Authorization header is set; ignored over stdio."
},
"name": {
"type": "string",
"description": "Human-readable app name."
},
"source": {
"type": "string",
"description": "Provider name (stripe, github, shopify, ...). Used for signature auto-detection."
},
"destinations": {
"type": "array",
"items": {
"type": "object",
"properties": {
"url": {
"type": "string",
"format": "uri"
}
},
"required": [
"url"
],
"additionalProperties": false
},
"description": "Destination URLs that should receive forwarded events."
}
},
"required": [
"name",
"source"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🔴anyhook_replay(api_key, id)
Re-send a stored event to its destinations. Replay does not consume monthly event quota, but the destination does run its handler again: a receiver that is not idempotent will process the event twice while debugging.
Input Schema
{
"type": "object",
"properties": {
"api_key": {
"type": "string",
"description": "API key (ahk_live_...) from anyhook_quickstart. Only needed over HTTP when no Authorization header is set; ignored over stdio."
},
"id": {
"type": "string",
"description": "Event ID to replay. Replay does not consume event quota."
}
},
"required": [
"id"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢anyhook_undelivered(api_key, appSlug, limit)
Show events for the given app that have not successfully reached any destination (failed or still retrying).
Input Schema
{
"type": "object",
"properties": {
"api_key": {
"type": "string",
"description": "API key (ahk_live_...) from anyhook_quickstart. Only needed over HTTP when no Authorization header is set; ignored over stdio."
},
"appSlug": {
"type": "string"
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 200
}
},
"required": [
"appSlug"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🔴anyhook_replay_failed(api_key, appSlug)
Re-send every failed event for the given app slug. Useful after fixing a downstream bug to recover queued work.
Input Schema
{
"type": "object",
"properties": {
"api_key": {
"type": "string",
"description": "API key (ahk_live_...) from anyhook_quickstart. Only needed over HTTP when no Authorization header is set; ignored over stdio."
},
"appSlug": {
"type": "string",
"description": "Bulk-replay every failed event for this app."
}
},
"required": [
"appSlug"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢anyhook_events(api_key, appSlug, source, status, limit)
List webhook events, most recent first: id, app, type, status, attempt, destination status code, latency, timestamp. Summaries only, no request headers or body — call anyhook_inspect with an id from here to read one event's payload. Uses your AnyHook account when connected, otherwise the local in-memory store.
Input Schema
{
"type": "object",
"properties": {
"api_key": {
"type": "string",
"description": "API key (ahk_live_...) from anyhook_quickstart. Only needed over HTTP when no Authorization header is set; ignored over stdio."
},
"appSlug": {
"type": "string",
"description": "Filter to a specific app slug (account mode)."
},
"source": {
"type": "string",
"description": "Filter by provider source (local mode)."
},
"status": {
"type": "string",
"description": "Filter by status. Account mode: queued|success|retrying|failed. Local mode: received|forwarded|failed|retrying."
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 200
}
},
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢anyhook_inspect(id, api_key)
Full detail for one event by id, including the inbound headers and body that anyhook_events omits, plus the destination's response. Payloads can be large and often contain personal data, so fetch one at a time, only when the body is needed. Account or local store.
Input Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "Event ID returned by anyhook_events."
},
"api_key": {
"type": "string",
"description": "API key (ahk_live_...) from anyhook_quickstart. Only needed over HTTP when no Authorization header is set; ignored over stdio."
}
},
"required": [
"id"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Community
Evidence