THE DEAD-LETTER INBOX FOR WEBHOOKS

Failed webhooks.
Second chances.

Stop ssh-ing into production for failed JSON. Hookjail keeps every delivery your app missed, shows a safe preview, and replays the exact request once your fix is live.

Your own webhook URL. 30 minutes. No account needed.

Redacted by default. Deliberate by design.
hookjail / deliveries / dl_8f21c40a
invoice.payment_failed

Stripe · received 2 minutes ago

Failed
1{
2 "id": "evt_1NxK2qLk8f21c4",
3 "type": "invoice.payment_failed",
4 "data": {
5 "customer_email": "••••••••",
6 "amount": "••••••••",
7 "currency": "usd"
8 }
9}

Response

504 timeout

Attempts

5 of 5

Payload

Redacted
Example deliveryHow replay works
Back on track.

Replay succeeded · 200 OK

187 ms

One inbox. The providers you already use.

Stripe◈ ShopifyGitHubPaddle& your own webhooks

FROM FAILED TO FIXED

Less log diving. More getting on with it.

No SSH sessions to find a missing JSON body. No improvised curl commands at 3am. Just three deliberate steps.

01 /

Catch what failed.

When retries run out, the story should not end. Keep the failed delivery, its response, and the context you need.

504 timeout → saved to inbox
02 /

See the whole story.

Inspect a redacted payload alongside stored headers and every attempt. Understand the failure without exposing customer data. Reveal the original only with a written reason.

"customer_email": "••••••••"
03 /

Give it another go.

Fixed the handler? Dry-run it, then replay the exact bytes with a fresh Hookjail signature. You are warned before repeating an event that already went through.

replay → 200 OK → back to building

A LITTLE LESS TO WORRY ABOUT

Sensitive payloads.
Sensible defaults.

Recovery should feel controlled. Every screen makes it clear what you can see, what will happen, and what gets recorded.

Explore the security approach

A safe preview comes first

Names, e-mails, amounts and card numbers are masked. Search covers metadata only, never payloads.

Every reveal has a reason

A written reason and an audit entry come before the original is shown, and the view closes itself.

Replay with the full context

Dry run first. Every replay is signed, and you are warned before repeating a delivered event.

Retention has a clear endpoint

You choose how long originals are kept. After that the record stays and replay stops.

EARLY ACCESS

Be first in when replay opens.

Hookjail is being built in the open. Leave your email and you get one message when permanent endpoints and replay are ready, including the pricing. Nothing else.

THE DETAILS

Good questions.

A few things you might want to know before handing over your webhooks.

Read the quickstart
How does Hookjail fit into my stack?

Create an endpoint, paste its Hookjail URL into your provider, and point it at your existing webhook handler. Hookjail stores each delivery, forwards it, and returns your handler’s real answer, so the provider’s own retries keep working. Failures land in your inbox.

Will replay create duplicate charges or emails?

It can if your application does not enforce idempotency. The replay flow shows the destination, previous replays, and original event key before you confirm. Your handler must use that key to prevent duplicate effects.

What will Hookjail cost?

Pricing is not announced yet. The 30-minute temporary webhook stays free. Replay and longer retention will be paid features; people on the early-access list hear about pricing first.

Can I use it without creating an account?

Yes. Guest access is designed for everyone: create a temporary webhook URL, send requests, and inspect their bodies and headers for 30 minutes without registration. Create an account only when you need permanent endpoints and longer retention.

What happens after 30 minutes?

The temporary webhook expires and its guest inbox closes. You can create a new URL without an account. For a permanent endpoint and longer retention, create an account. Guest access is separate from the registered Free plan.

Who can access the original payload?

Signed-in members of your workspace, and only through Reveal payload: it needs a written reason, is recorded in the audit log before the data is shown, and closes after five minutes. Payloads are encrypted with a per-workspace key. Today the master keys live in Cloudflare Worker secrets; the security page lists exactly what we do and do not claim.

Your webhook URL is one click away.

Create it without signing up. Receive and inspect requests for 30 minutes.

Use for free