Hookden

Webhook capture bins for agents: get a URL, wait for webhooks, set replies, verify signatures.

사용해야 할까요

품질 및 안전성

A
설명 품질
100%
스키마 완전성
90%
이름 품질
100%
오염 위험
100%
권한 일치
100%
프로토콜 준수
100%

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~1,653토큰 (도구 정의)
~1.5 KB일반적인 응답 크기
중간 정도의 주의 영향 (128k 컨텍스트의 1.29%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "hookden": {
      "url": "https://hookden.pages.dev/mcp"
    }
  }
}

원격 엔드포인트

https://hookden.pages.dev/mcpstreamable-http

할 수 있는 일

도구 목록

도구 (7)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
🟡create_bin

Create a new webhook capture bin. Returns a public capture_url — point any webhook (Stripe, GitHub, Slack, your own service…) at it and every request sent there (any method, any subpath, headers + raw body) is stored. Then read what arrived with list_captures, get_capture, or wait_for_capture. Anonymous bins keep requests ~24h. No auth needed.

입력 스키마

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟢list_captures(bin, after, limit)

List requests captured by a bin, oldest first. Compact summaries (id, method, path, time, content-type, body size, signature status). Use get_capture for full headers/body. Pass `after` (a capture id) to only see newer captures.

입력 스키마

{
  "type": "object",
  "properties": {
    "bin": {
      "type": "string",
      "description": "bin id (or custom slug) from create_bin"
    },
    "after": {
      "type": "integer",
      "description": "only captures with id greater than this (default 0)"
    },
    "limit": {
      "type": "integer",
      "description": "max results, 1-50 (default 20)"
    }
  },
  "required": [
    "bin"
  ],
  "additionalProperties": false
}
🟢get_capture(bin, id)

Get one captured request in full: method, path, query, every header, and the body. Binary bodies are returned base64-encoded (up to 8KB, with a URL for the raw bytes).

입력 스키마

{
  "type": "object",
  "properties": {
    "bin": {
      "type": "string",
      "description": "bin id or slug"
    },
    "id": {
      "type": "integer",
      "description": "capture id from list_captures / wait_for_capture"
    }
  },
  "required": [
    "bin",
    "id"
  ],
  "additionalProperties": false
}
🟡wait_for_capture(bin, after_id, timeout_seconds)

Block until the next request arrives at a bin (or a timeout passes), then return it in full. Ideal flow: create_bin → configure the webhook sender → trigger it → wait_for_capture. If `after_id` is omitted, waits for the next capture after "now". Returns timed_out:true instead of erroring when nothing arrives.

입력 스키마

{
  "type": "object",
  "properties": {
    "bin": {
      "type": "string",
      "description": "bin id or slug"
    },
    "after_id": {
      "type": "integer",
      "description": "return the first capture with id greater than this; default = latest id at call time"
    },
    "timeout_seconds": {
      "type": "integer",
      "description": "1-45 seconds to wait (default 20)"
    }
  },
  "required": [
    "bin"
  ],
  "additionalProperties": false
}
🟡send_test_webhook(bin, example)

Simulate a webhook delivery into a bin — no external sender or HTTP client needed. Seeds one realistic, clearly-labeled sample capture (default: a GitHub push event) and returns it in full, so you can exercise the whole loop (create_bin → send_test_webhook → list_captures / get_capture) entirely from MCP. Pass `example` to pick a provider payload from the /examples library (e.g. "stripe-payment-intent-succeeded", "slack-event-callback", "shopify-order-created"). Sample captures are marked as simulated and never count as real webhook traffic.

입력 스키마

{
  "type": "object",
  "properties": {
    "bin": {
      "type": "string",
      "description": "bin id (or custom slug) from create_bin"
    },
    "example": {
      "type": "string",
      "description": "optional example payload slug from /examples (default: a GitHub push event)"
    }
  },
  "required": [
    "bin"
  ],
  "additionalProperties": false
}
🟡set_response(bin, status, content_type, body, headers, ...)

Configure what a bin replies to webhook senders: HTTP status, content-type, body, custom response headers, optional delay. Body and header values support {{…}} templates rendered per-request from the INCOMING delivery — {{body.challenge}}, {{query.hub.challenge}}, {{header.x-hook-secret}}, {{hmac_sha256 body.plainToken YOUR_SECRET}} — so a bin can pass provider verification handshakes with zero code: Slack URL verification (body {{body.challenge}}), Zoom CRC (JSON with the hmac_sha256 helper), Meta/WhatsApp GET echo (text/plain {{query.hub.challenge}}), Strava (JSON {"hub.challenge":"{{query.hub.challenge}}"}), Asana (response header X-Hook-Secret: {{header.x-hook-secret}}). Only the fields you pass change; everything else keeps its current value. Works on bins created via create_bin by this same client; the incoming request is still captured in full either way.

입력 스키마

{
  "type": "object",
  "properties": {
    "bin": {
      "type": "string",
      "description": "bin id (or custom slug) from create_bin"
    },
    "status": {
      "type": "integer",
      "description": "HTTP status to respond with, 100-599 (bins default to 200)"
    },
    "content_type": {
      "type": "string",
      "description": "Content-Type of the response (e.g. application/json, text/plain)"
    },
    "body": {
      "type": "string",
      "description": "response body, max 10000 chars; {{…}} templates allowed"
    },
    "headers": {
      "type": "object",
      "additionalProperties": {
        "type": "string"
      },
      "description": "custom response headers as name→value (max 10; values may use {{…}} templates). Pass {} to clear. Hop-by-hop/security headers (set-cookie, location, strict-transport-security…) are rejected."
    },
    "delay_ms": {
      "type": "integer",
      "description": "artificial response delay in milliseconds, 0-10000 (for testing sender timeouts/retries)"
    }
  },
  "required": [
    "bin"
  ],
  "additionalProperties": false
}
🟢verify_signature(scheme, secret, headers, body, body_base64, ...)

Verify a webhook signature against a secret — 25 provider-exact schemes plus a generic HMAC mode, the same engine that computes ✓/✗ badges on captures. Covers HMAC-SHA256 (GitHub, Stripe, Svix/Standard Webhooks, Shopify-style base64, URL-signing Square/HubSpot/Trello…), ECDSA (SendGrid), RSA (Kick) and HMAC-MD5 (Patreon). Pass the scheme, the secret, the delivery's headers, and the BYTE-EXACT raw body (body_base64 for binary). The secret is used only for this one in-memory computation — never stored or logged. No bin needed. If verification fails, the #1 cause is a re-serialized body: point the real webhook at a capture bin (create_bin) to get the true raw bytes first.

입력 스키마

{
  "type": "object",
  "properties": {
    "scheme": {
      "type": "string",
      "enum": [
        "github",
        "stripe",
        "svix",
        "calendly",
        "mailchimp",
        "mux",
        "workos",
        "paddle",
        "notion",
        "patreon",
        "intercom",
        "zendesk",
        "trello",
        "webflow",
        "square",
        "hubspot",
        "twitch",
        "frameio",
        "buildkite",
        "airtable",
        "mailgun",
        "adyen",
        "sendgrid",
        "kick",
        "hmac"
      ],
      "description": "signature scheme (usually the provider name); \"hmac\" = generic HMAC over the raw body"
    },
    "secret": {
      "type": "string",
      "description": "signing secret or key exactly as the provider shows it (sendgrid/kick: the PUBLIC verification key)"
    },
    "headers": {
      "type": "object",
      "additionalProperties": {
        "type": "string"
      },
      "description": "the delivery's HTTP headers — at least the signature/timestamp headers; names are case-insensitive"
    },
    "body": {
      "type": "string",
      "description": "raw request body, byte-exact as the provider sent it (not re-serialized!)"
    },
    "body_base64": {
      "type": "string",
      "description": "alternative to `body` for binary payloads: base64 of the raw body bytes"
    },
    "url": {
      "type": "string",
      "description": "full delivery URL — REQUIRED for square, hubspot and trello (the URL is part of the signed string)"
    },
    "method": {
      "type": "string",
      "description": "HTTP method of the delivery (hubspot v3 signs it; default POST)"
    },
    "signature_header": {
      "type": "string",
      "description": "scheme \"hmac\" only: which header carries the signature (default x-signature)"
    }
  },
  "required": [
    "scheme",
    "secret"
  ],
  "additionalProperties": false
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 7개
검증됨버전이 기록되지 않음도구 7개