Cosmovex Tools

Webhook signature failing or payload unclear? Get a permanent URL, watch requests arrive live, check the signature here.

What Hookwatch Webhook Tester does

A webhook URL that doesn't expire, a live view of every request, and Stripe, GitHub, Shopify and Slack signature checks in your browser.

Webhooks fail where you cannot see them: a 400 from your handler, a signature mismatch, a payload shape you guessed wrong. Hookwatch gives you a URL on this page the moment it loads. Paste it into Stripe, GitHub, Shopify, Slack, Twilio or any service that sends webhooks, and every request it sends appears here live, without a refresh.

Each request is stored exactly as it arrived: the method, the full path after your inbox URL, the query string, every header in arrival order and the raw body byte for byte. JSON opens as a collapsible tree, form posts as a table, XML pretty-printed, and anything binary as a hex dump, so you can see what was really sent rather than what a parser made of it.

The Signature tab answers the question most webhook bugs come down to. Pick the provider (it is detected from the headers), paste your signing secret and see Valid or Invalid, the digest we expected next to the one received, and the exact string that was signed. Stripe and Slack timestamps get a five-minute tolerance check, Twilio's URL-plus-parameters rule is applied for you, and a generic HMAC mode covers everyone else. The check runs with WebCrypto in your browser; the secret is never sent anywhere.

To reproduce a delivery, copy any request as a curl, HTTPie or fetch command that sends the same method, headers and body bytes, or replay it straight to your dev server from the browser. Replay depends on your server allowing CORS from this page, and the tool tells you plainly when that is what blocked it. Search, a JSONPath filter such as $.type == 'invoice.paid' and a field-by-field diff of two payloads help you find the one request that matters.

The free inbox stores 100 requests a day and keeps the newest 50 for 7 days. Pro is $5 a month because the inbox keeps receiving while your laptop is closed: up to 10 inboxes with readable URLs, 5,000 requests a day kept for 30 days, a custom response so you can test how a sender retries a 500, a team invite link with notes, and NDJSON or HAR export. An inbox URL stays live as long as it receives at least one request every 30 days.

API & HTTP webhook tester verify stripe webhook signature onlinegithub webhook signature testershopify webhook hmac verifyslack request signature verifytwilio signature validator
Open Hookwatch Webhook Tester

Free vs Pro

Feature Free $0 · no account Pro $5/mo · 3 browsers
A permanent inbox URL, ready on first visit with no sign-up Included Included
Live request stream: method, path, query, headers, raw body, size and time Included Included
Body views: JSON tree, pretty, form fields, XML, raw and hex Included Included
Signature checks in your browser for Stripe, GitHub, Shopify, Slack, Twilio, Svix / Standard Webhooks and any HMAC Included Included
Search and JSONPath filters, plus a field-by-field diff of two requests Included Included
Copy as curl, HTTPie or fetch; replay to localhost from the browser Included Included
100 stored requests a day, newest 50 kept for 7 days, 256 KB per request Included Included
Up to 10 inboxes with your own names and a readable /hook/your-name URL — Pro
5,000 stored requests a day per inbox, newest 1,000 kept for 30 days — Pro
Custom response per inbox: status code, content type, headers and body — Pro
Team view: an invite link to watch an inbox live and add notes on requests — Pro
Signature presets saved with the inbox for everyone watching it — Pro
Export an inbox as NDJSON or HAR, and download any raw body — Pro

Pro is $5/mo, billed monthly. Checkout and the licence key are handled by Dodo Payments (merchant of record). By buying you agree to the Terms and Privacy Policy.

Questions

Is Hookwatch Webhook Tester free?

Yes, with no account and no install. The free plan includes: A permanent inbox URL, ready on first visit with no sign-up; Live request stream: method, path, query, headers, raw body, size and time; Body views: JSON tree, pretty, form fields, XML, raw and hex; Signature checks in your browser for Stripe, GitHub, Shopify, Slack, Twilio, Svix / Standard Webhooks and any HMAC; and 3 more. Pro ($5/mo, billed monthly, cancel anytime) adds: Up to 10 inboxes with your own names and a readable /hook/your-name URL; 5,000 stored requests a day per inbox, newest 1,000 kept for 30 days; Custom response per inbox: status code, content type, headers and body; Team view: an invite link to watch an inbox live and add notes on requests; and 2 more.

Does Hookwatch Webhook Tester upload my data?

Yes, by design. Requests sent to your inbox URL (method, path, query, headers, body, a /24 or /48 IP prefix and the country) are stored in Google Firebase in the United States so they arrive while this tab is closed. Free inboxes keep the newest 50 for 7 days, Pro the newest 1,000 for 30 days, and an inbox idle for 30 days is deleted. Signing secrets and signature checks stay in your browser. See the Privacy Policy for retention and deletion.

Do I need to install anything?

No. Open the page and start working. It works on desktop and mobile browsers.

How does the Pro licence work?

Pro is a monthly subscription handled by Dodo Payments (our merchant of record). You receive a licence key by email and paste it under "Have a key?" inside the tool. One key works on up to 3 browsers.

Does the webhook URL expire?

No, as long as it receives at least one request every 30 days. Free inboxes keep the newest 50 requests for 7 days; Pro keeps the newest 1,000 for 30 days.

Is my signing secret sent anywhere?

No. Signature checks run with your browser's WebCrypto against the raw body we stored. The secret is saved only in this browser's local storage, so you do not have to paste it again, and you can clear it with Forget.

Which webhook signatures can it verify?

Stripe (Stripe-Signature, with the timestamp tolerance), GitHub (X-Hub-Signature-256 and the older SHA-1 header), Shopify (X-Shopify-Hmac-Sha256), Slack (X-Slack-Signature v0), Twilio (X-Twilio-Signature), Svix / Standard Webhooks used by Clerk and Resend, and a generic HMAC-SHA256, SHA-1 or SHA-512 mode with your own header, prefix, encoding and signed-payload template.

Where are the requests stored, and who can see them?

Requests are stored in Google Firebase so they arrive while this tab is closed. Only the browser that created the inbox can read them, plus anyone you give a Pro team invite link to. Webhooks can carry customer data, so delete requests when you are done; Settings has Delete all requests and Delete inbox.

Can it forward requests to my server?

Not from the server in this version. Copy any request as curl and run it in a terminal, or use Replay to send it from your browser to localhost or a dev URL. Replay works when your server allows CORS from this page; the tool tells you when CORS was the problem.

Why is Pro a subscription?

The inbox receives and stores requests around the clock, even when your browser is closed, which is a real running cost. Pro is $5 a month and you can cancel any time; the inbox goes back to the free limits.

What are the limits?

Free: 1 inbox, 100 stored requests a day (UTC), the newest 50 kept for 7 days, 256 KB per request, a fixed 200 OK response. Pro: up to 10 inboxes, 5,000 requests a day each, the newest 1,000 kept for 30 days, and a custom response. Bodies over 256 KB get a 413 and a summary row.