Catch what failed.
When retries run out, the story should not end. Keep the failed delivery, its response, and the context you need.
504 timeout → saved to inboxStop ssh-ing into production for failed JSON. Hookjail keeps every delivery your app missed, shows a safe preview, and replays the exact request once your fix is live.
Your own webhook URL. 30 minutes. No account needed.
Stripe · received 2 minutes ago
{ "id": "evt_1NxK2qLk8f21c4", "type": "invoice.payment_failed", "data": { "customer_email": "••••••••", "amount": "••••••••", "currency": "usd" }}Response
504 timeoutAttempts
5 of 5Payload
RedactedReplay succeeded · 200 OK
One inbox. The providers you already use.
FROM FAILED TO FIXED
No SSH sessions to find a missing JSON body. No improvised curl commands at 3am. Just three deliberate steps.
When retries run out, the story should not end. Keep the failed delivery, its response, and the context you need.
504 timeout → saved to inboxInspect a redacted payload alongside stored headers and every attempt. Understand the failure without exposing customer data. Reveal the original only with a written reason.
"customer_email": "••••••••"Fixed the handler? Dry-run it, then replay the exact bytes with a fresh Hookjail signature. You are warned before repeating an event that already went through.
replay → 200 OK → back to buildingA LITTLE LESS TO WORRY ABOUT
Recovery should feel controlled. Every screen makes it clear what you can see, what will happen, and what gets recorded.
Explore the security approachNames, e-mails, amounts and card numbers are masked. Search covers metadata only, never payloads.
A written reason and an audit entry come before the original is shown, and the view closes itself.
Dry run first. Every replay is signed, and you are warned before repeating a delivered event.
You choose how long originals are kept. After that the record stays and replay stops.
EARLY ACCESS
Hookjail is being built in the open. Leave your email and you get one message when permanent endpoints and replay are ready, including the pricing. Nothing else.
THE DETAILS
A few things you might want to know before handing over your webhooks.
Read the quickstartCreate an endpoint, paste its Hookjail URL into your provider, and point it at your existing webhook handler. Hookjail stores each delivery, forwards it, and returns your handler’s real answer, so the provider’s own retries keep working. Failures land in your inbox.
It can if your application does not enforce idempotency. The replay flow shows the destination, previous replays, and original event key before you confirm. Your handler must use that key to prevent duplicate effects.
Pricing is not announced yet. The 30-minute temporary webhook stays free. Replay and longer retention will be paid features; people on the early-access list hear about pricing first.
Yes. Guest access is designed for everyone: create a temporary webhook URL, send requests, and inspect their bodies and headers for 30 minutes without registration. Create an account only when you need permanent endpoints and longer retention.
The temporary webhook expires and its guest inbox closes. You can create a new URL without an account. For a permanent endpoint and longer retention, create an account. Guest access is separate from the registered Free plan.
Signed-in members of your workspace, and only through Reveal payload: it needs a written reason, is recorded in the audit log before the data is shown, and closes after five minutes. Payloads are encrypted with a per-workspace key. Today the master keys live in Cloudflare Worker secrets; the security page lists exactly what we do and do not claim.
Create it without signing up. Receive and inspect requests for 30 minutes.