Webhook Toolkit
Webhook URLs for AI agents: receive, wait for, replay, sign and verify webhooks (Stripe, GitHub…).
¿Debería usar esto?
Calidad y seguridad
Hallazgos (1)
- LOWen get_webhook_request
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"webhook-toolkit": {
"command": "npx",
"args": [
"webhook-toolkit"
]
}
}
}Paquetes ejecutables
0.1.1stdioPuntos de conexión remotos
https://webhook-toolkit.com/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (10)
🟡create_webhook_url(name)
Create a public HTTPS URL that captures every request sent to it (any method, any sub-path). Use it when you need an endpoint to receive a webhook from a third-party service while building or debugging an integration. Returns the URL to configure in the service and a live inspector link for the human.
Esquema de entrada
{
"type": "object",
"properties": {
"name": {
"description": "Label, e.g. 'stripe-test'",
"type": "string",
"maxLength": 60
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢list_webhook_urls
List the webhook URLs of the account behind the API key (requires an API key).
Esquema de entrada
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢wait_for_webhook(token, timeout_seconds, after)
Block until the next request reaches a webhook URL (or the timeout elapses), then return it in full: method, path, headers, body, detected provider and event. Use right after triggering an action that should send a webhook. Call again with `after` set to the last request's createdAt to wait for the following one.
Esquema de entrada
{
"type": "object",
"properties": {
"token": {
"type": "string",
"description": "Token of the webhook URL (the part after /r/)"
},
"timeout_seconds": {
"description": "Default 30, max 50",
"type": "integer",
"minimum": 1,
"maximum": 50
},
"after": {
"description": "ISO timestamp: only requests strictly newer than this. Default: now.",
"type": "string"
}
},
"required": [
"token"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢list_webhook_requests(token, limit)
List the most recent requests captured by a webhook URL, newest first (summaries; use get_webhook_request for one full request).
Esquema de entrada
{
"type": "object",
"properties": {
"token": {
"type": "string"
},
"limit": {
"description": "Default 10",
"type": "integer",
"minimum": 1,
"maximum": 50
}
},
"required": [
"token"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢get_webhook_request(token, request_id)
Return one captured request in full (headers, raw body, detected provider/event).
Esquema de entrada
{
"type": "object",
"properties": {
"token": {
"type": "string"
},
"request_id": {
"type": "string"
}
},
"required": [
"token",
"request_id"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡set_webhook_response(token, status, body, content_type)
Choose what the webhook URL answers to callers (status code, body, content type) — e.g. return 500 to test the sender's retries, or a specific JSON/XML body the service expects.
Esquema de entrada
{
"type": "object",
"properties": {
"token": {
"type": "string"
},
"status": {
"type": "integer",
"minimum": 100,
"maximum": 599
},
"body": {
"type": "string",
"maxLength": 10000
},
"content_type": {
"type": "string",
"maxLength": 120
}
},
"required": [
"token"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡replay_webhook_request(token, request_id, target_url)
Re-send a captured request (same method, headers and raw body) to a PUBLIC URL and return the target's response. Localhost and private IPs are refused here: for localhost use the CLI (`npx webhook-toolkit replay`) or the local MCP server (`npx webhook-toolkit mcp`).
Esquema de entrada
{
"type": "object",
"properties": {
"token": {
"type": "string"
},
"request_id": {
"type": "string"
},
"target_url": {
"type": "string",
"format": "uri"
}
},
"required": [
"token",
"request_id",
"target_url"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡sign_webhook_payload(provider, secret, payload, event_type, target_url)
Build a webhook body with a VALID signature header for a provider, to test a handler's signature verification without triggering a real event. Providers: stripe, github, shopify, slack, twilio, mailgun. Returns the headers, the exact body to send and a ready-to-run curl command.
Esquema de entrada
{
"type": "object",
"properties": {
"provider": {
"type": "string",
"enum": [
"stripe",
"github",
"shopify",
"slack",
"twilio",
"mailgun"
]
},
"secret": {
"type": "string",
"description": "The webhook signing secret configured in your handler (whsec_… for Stripe)"
},
"payload": {
"description": "JSON payload (or form fields as JSON for Twilio). Default: a realistic sample event.",
"type": "string"
},
"event_type": {
"description": "Sample event to use when no payload is given, e.g. checkout.session.completed",
"type": "string"
},
"target_url": {
"description": "Handler URL (required for Twilio, whose signature covers the URL)",
"type": "string"
}
},
"required": [
"provider",
"secret"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢verify_webhook_signature(provider, secret, raw_body, signature, timestamp, ...)
Check whether a webhook signature is valid for a raw body and a secret, and diagnose why it fails (wrong secret, whitespace, re-serialized JSON body, expired timestamp, wrong URL for Twilio). Providers: stripe, github, shopify, slack, twilio.
Esquema de entrada
{
"type": "object",
"properties": {
"provider": {
"type": "string",
"enum": [
"stripe",
"github",
"shopify",
"slack",
"twilio"
]
},
"secret": {
"type": "string"
},
"raw_body": {
"type": "string",
"description": "The raw request body exactly as received"
},
"signature": {
"type": "string",
"description": "The signature header value (Stripe-Signature, X-Hub-Signature-256, X-Shopify-Hmac-Sha256, X-Slack-Signature, X-Twilio-Signature)"
},
"timestamp": {
"description": "Slack only: X-Slack-Request-Timestamp",
"type": "string"
},
"url": {
"description": "Twilio only: the full URL Twilio called",
"type": "string"
}
},
"required": [
"provider",
"secret",
"raw_body",
"signature"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢explain_webhook_request(token, request_id, mode, language)
AI analysis of a captured request. mode=explain: who sent it, which event, key fields, how to verify the signature, pitfalls. mode=handler: complete receiving code that verifies the signature and handles this event. Included in paid plans; anonymous and free users get 3 trials.
Esquema de entrada
{
"type": "object",
"properties": {
"token": {
"type": "string"
},
"request_id": {
"type": "string"
},
"mode": {
"type": "string",
"enum": [
"explain",
"handler"
]
},
"language": {
"description": "Handler language (mode=handler). Default node.",
"type": "string",
"enum": [
"node",
"nextjs",
"python",
"php",
"go",
"ruby"
]
}
},
"required": [
"token",
"request_id"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}Comunidad
Evidencia