Skip to main content
Webhook Debugger & Logger gives you disposable webhook endpoints that capture the complete request envelope — headers, body, query params, response, timing, and IP — and expose a searchable log API, a live SSE event stream, and one-click replay. It works with Stripe, GitHub, Shopify, Slack, and any custom HMAC provider, and runs on the Apify platform or self-hosted with Node.js or Docker.

What you get

Capture and inspect

Every incoming webhook is stored with full request and response metadata, including headers, payload, status code, latency, and sender IP.

Live event stream

Watch events appear in real time over a Server-Sent Events feed at /log-stream — no polling required.

Replay captured traffic

Resend any stored event to a new destination URL after you fix a bug, without asking your provider to re-deliver.

Forward to another server

Pipe every captured request to a downstream service while keeping a full audit trail, with automatic retries and circuit breaking.

Mock API responses

Return custom status codes, headers, bodies, and artificial latency to simulate how your application handles slow or failing callbacks.

Verify provider signatures

Validate Stripe, GitHub, Shopify, Slack, and custom HMAC signatures automatically, with replay-attack protection.

Key features

When to use this instead of a generic request bin

A generic request bin shows you raw HTTP dumps. Webhook Debugger & Logger goes further:
  • Searchable, queryable logs — filter and paginate captured events through a documented API, not just a web UI.
  • Replay and forwarding — resend stored events to a new target or pipe live traffic to a downstream service.
  • Provider signature verification — validate Stripe, GitHub, Shopify, Slack, and custom HMAC signatures with one config option.
  • API mocking — simulate custom status codes, response bodies, and artificial latency without a separate mock server.
  • Slack and Discord alerts — get notified immediately when capture, validation, or downstream delivery fails.
  • Operational endpoints/health, /ready, and /system/metrics make it suitable for automated test harnesses and CI pipelines.

Supported providers

Signature verification is built in for the following providers. Select yours in the signatureVerification input and supply the shared secret — no custom middleware required.
  • StripeStripe-Signature header with HMAC-SHA256 and timestamp tolerance
  • GitHubX-Hub-Signature-256 header with HMAC-SHA256
  • ShopifyX-Shopify-Hmac-SHA256 header with HMAC-SHA256
  • SlackX-Slack-Signature with version prefix and timestamp replay protection
  • Custom HMAC — configurable header name, algorithm (sha256 or sha1), and encoding (hex or base64)
Generated webhook URLs are public by default. Set authKey, allowedIps, or signatureVerification before pointing real provider traffic at your endpoints.