Build Webhook.site

YESreplaces $9/mosaves $108/yrback to the verdict

0%0 of 17 items done

Saved on this device only. Tick prerequisites first, then work the phases in order · do not start one until the checks above it pass.

A webhook inspector you host: mint a URL, catch anything sent to it with headers and body intact, watch requests arrive live, replay one to your localhost, and let bins expire. Nine dollars a month buys permanence and scripting; this buys understanding.

estimated effort one sittingthe files for this build are in the project pack

RuntimeNode 22, node:http and node:sqliteLive updatesA 2-second vanilla-JS pollHostingA VPS behind Caddy

Before step 1

Everything below is assumed from the first step. Tick each one when you actually have it, not when you plan to.

  1. installfree

    Why Everything in this build runs on it: the server, the scripts, the tests.

    Get it Download the LTS installer from nodejs.org, or install with your package manager (brew install node, or nvm install 22). Restart the terminal afterwards. open ↗

    Verify node --version prints v22 or higher

  2. installfree

    Why Every step below is a command you type or a file you edit.

    Get it VS Code (code.visualstudio.com), Cursor or Zed. Open a folder for the project and use the editor's built-in terminal. open ↗

    Verify You can open a folder and run a command in its terminal

  3. installfree

    Why History for your code, and the way most hosts deploy.

    Get it Install from git-scm.com or with your package manager, then run git init in the project folder once it exists. open ↗

    Verify git --version prints a version

  4. about $5 a month

    Why This needs one process running all the time with a public address. The URL must be reachable from the services that call it.

    Get it Hetzner Cloud (from about 4 EUR), DigitalOcean or Fly.io. Ubuntu 24.04, the smallest size. You need SSH access and a public IP. Only needed for the deploy phase; develop locally first. open ↗

  5. roughly $10 a year, or free on an existing domain

    Why A public address you own, so links you share never break when a provider changes.

    Get it Register at Cloudflare Registrar, Porkbun or Namecheap, or use a subdomain of one you already own. You add one DNS record in the deploy phase. open ↗

  6. installfree

    Why Automatic HTTPS in front of the Node process. Without TLS the browser features this relies on (and your visitors' trust) do not work.

    Get it On the VPS: follow the install steps at caddyserver.com/docs/install for Ubuntu. One Caddyfile with your domain and a reverse_proxy line is the whole config. open ↗

    Verify caddy version prints a version on the server

  7. have readyfree

    Why Phase 1 and 3 need real deliveries.

    Get it Stripe test mode, a GitHub repository webhook, or curl.

Data model

Create these before the first phase that stores anything. Changing a table later is the expensive kind of change.

- bins: id (uuid), created_at, expires_at, note
- requests: id, bin_id, received_at, method, path, query, headers (JSON), body (text or base64 when binary), content_type, size, ip_hash

Environment variables

These go in a .env file the app reads at startup. The pack's .env.example is this table as a file · copy it, never commit the filled-in version.

VariableNeededExampleWhere the value comes from
PORTrequired3000Any free port.
DATABASE_PATHrequired./data/hooks.dbSQLite file.
SITE_URLrequiredhttps://hooks.yourdomain.comPublic base URL.
BIN_TTL_DAYSoptional7Default expiry for a bin.
ADMIN_USERrequiredadminAny username for the basic-auth admin pages.
ADMIN_PASSsecretrequiredchange-me-to-a-long-random-stringGenerate one: openssl rand -base64 24. Never reuse a real password.

The build, in order

  1. Catch anything

    Any method, any subpath, stored intact, body capped.

    1. bins (id, created_at, expires_at, note), requests (id, bin_id, received_at, method, path, query, headers JSON, body, content_type, size, ip_hash).

      terminal
      mkdir hooks && cd hooks && git init && npm init -y && npm pkg set type=module
      mkdir -p data && cp .env.example .env
    done when · tick each as it passes
  2. Inspector

    Newest first, detail view, copy as curl, live poll.

    done when · tick each as it passes
  3. Replay

    Re-send a stored request to a URL you type.

    done when · tick each as it passes
  4. Bins and retention

    Mint, expire, prune, rate limit.

    done when · tick each as it passes
  5. Deploy

    HTTPS, service, README.

    1. Files README.md

    done when · tick each as it passes
what this build does not replace
after v1, if you want it

Need the files? The project pack on the verdict page hands your agent the whole brief · more dev tools.