Introduction
WebhookVault captures every webhook sent to your endpoints, keeps it, and lets you inspect, search, replay and forward it, from the dashboard or over the API.
WebhookVault gives every webhook a durable home. Point a sender at a capture URL and the vault stores the request in full, headers, body, source and timing, answers the sender whatever you configured, and optionally relays it onward with retries and a full per-attempt delivery history. Nothing is silently dropped: when something can't be stored in full or delivered, that fact is recorded where you can see it.
The REST API covers endpoints, captured requests, deliveries, actions, transformations, watchdogs, alert channels and the recycle bin, including things a dashboard can't, like blocking until an expected webhook arrives in a CI job. Some areas are dashboard-only, for example the Library (connections and saved requests), workspace contacts, the activity log, usage, team and API key management, billing and export. API access starts on the Solo plan.
Choose your path
Capture your first webhook
Create an endpoint, send a test with curl, open the stored request. Dashboard only, no API key, works on the Free plan.
Quickstart: API (Solo and up)
A capture URL in one call, a stored request seconds later. The five-minute API path.
Test webhooks in CI
Ephemeral endpoints + the await API: assert that a webhook actually fired, in one HTTP call.
Forward and replay
Relay captures onward with retries, dead-lettering, and re-delivery of anything, any time.
API reference
Every endpoint, with schemas, examples and a live playground.
What you can do
| Area | Capability |
|---|---|
| Capture | Any method, any content type, binary included. The endpoint answers senders with the status, headers and body you configure. |
| Inspect | Search stored requests by method, delivery state, time window and text; read any of them in full, forever within your retention window. |
| Forward | Relay captures to your own URL in the background: retries with backoff, dead-letter parking, per-attempt history. |
| Replay | Re-deliver any stored request: one at a time, or hundreds queued in bulk. |
| CI mode | Create self-expiring endpoints from a pipeline and block until a matching webhook arrives. |
Principles
- The vault never lies. A
200from a capture URL means the request is stored. A request that exceeded your payload cap is stored as an oversize trace, marked as such, never a fake payload. - Errors are contracts. Every non-2xx API response is an RFC 9457 problem with a stable machine
code. Parse the code; show the detail. See Errors. - Limits are visible. Rate limits answer
429withRetry-After; plan caps explain themselves in the response instead of failing mysteriously. See Rate limits.
Where next?
- Quickstart: dashboard: first webhook captured on the Free plan
- Quickstart: API (Solo and up): the same loop from a script
- Concepts: endpoints, captured requests, deliveries
- Authentication: API keys and how to treat them
- Transformations: shape a delivery with a declarative rule; previewable, LLM-writable