Send webhooks to your customers and receive them from Stripe, GitHub and the rest. Retries, signatures, a customer portal, replay and a log of every attempt. An open-source webhook gateway under MIT.
Verifies webhooks from
Product
Delivery your customers can check
Your app makes one API call. Railhook signs it, delivers it to every subscribed endpoint and keeps trying when their server is down.
Retries + failed messages
408, 429, 5xx and timeouts retry for up to 31 hours, then wait in Failed messages for you to resend.
Signatures + rotation
Standard Webhooks headers any library verifies. During a rotation, requests carry both signatures.
Customer portal
Embed a page where your customers add endpoints, see their deliveries and retry the failed ones.
| Endpoint | order.paid | order.refunded | user.created |
|---|---|---|---|
| Portalhooks.northwind.io | ✓ 200 | ✓ 200 | ✓ 204 |
| api.acme-shop.com | ✓ 200 | ✕ 503 | ✓ 200 |
| erp.globex.com | ✕ refused | ✕ refused | ✓ 200 |
| billing.initech.dev | ✓ 200 | ✓ 200 | ✓ 200 |
| crm.umbrella.co | ✓ 202 | ✕ 429 | ✓ 202 |
| hooks.stark.io | ✓ 200 | ✓ 200 | ✕ 500 |
| notify.wayne.app | ✓ 200 | ✓ 200 | ✓ 200 |
A buffer in front of your app
Point Stripe or GitHub at Railhook instead of at your app. It checks the signature, answers them at once and forwards to you with the same retries.
Signature verification
Stripe, GitHub, Shopify, Slack, Twilio, SendGrid or any HMAC. Forged requests are refused and still logged.
Forward with retries
If your app is down, the request waits in Railhook and is forwarded when it comes back.
Replay + Time Machine
Resend a past time range to your app as new deliveries, for example after fixing a bug in your handler.
| Source | Signature | Forwarded to | Result |
|---|---|---|---|
| Stripe | ✓ verified | billing.internal/stripe | ✓ 200 |
| GitHub | ✓ verified | ci.internal/github | ✓ 200 |
| Shopify | ✓ verified | orders.internal/shopify | ✕ 503 · retry 1m |
| Unknown | ✕ invalid | — | ✕ rejected |
| Twilio | ✓ verified | sms.internal/twilio | ✓ 200 |
| SendGrid | ✓ verified | mail.internal/events | ✓ 202 |
| Slack | ✓ verified | ops.internal/slack | ✓ 200 |
Delivery
| Attempt | 1 | 2 | 3 | 4 | 5 | 6 | 7 | |
|---|---|---|---|---|---|---|---|---|
| Waits | — | 1m | 5m | 15m | 1h | 6h | 24h | → Failed messages |
| Since first try | 0 | 1m | 6m | 21m | 1h 21m | 7h 21m | 31h 21m |
Retried: 408, 429, 5xx, timeouts, connection errors. Not retried: other 4xx, they go straight to Failed messages. Send an Idempotency-Key and a repeated call returns the event you already created.
Self-hosting
# one command: writes .env with generated secrets,
# gets a certificate and starts the stack
curl -fsSL https://railhook.io/install.sh | bash -s -- \
--domain hooks.example.com --email ops@example.com
# day two
./railhook status
./railhook upgrade # backs up first
./railhook backupPostgreSQL and Redis in one Compose file
The self-hosted version is the whole product: every feature, no event limits, no licence key.
--domainRailhook Cloud: 10,000 events a month, 3 projects, 7 days of history. Self-hosted: everything, MIT.