Webhook infrastructure
you can run yourself

Send webhooks to your customers and receive them from Stripe, GitHub and the rest. Retries, signatures, a customer portal, replay and a log of every attempt. An open-source webhook gateway under MIT.

order.paid → api.acme-shop.com/webhooksdelivered on attempt 5
114:02:07503 Service Unavailablenext 1m
214:03:07503 Service Unavailablenext 5m
314:08:07connection refusednext 15m
414:23:07502 Bad Gatewaynext 1h
515:23:07200 OK · delivered141 ms

Verifies webhooks from

  • Stripe
  • GitHub
  • Shopify
  • Slack
  • Twilio
  • SendGrid
  • + Any HMAC

Product

Send webhooks to your customers and receive
them from Stripe, GitHub and others.

Delivery your customers can check

Outgoing webhooks

Your app makes one API call. Railhook signs it, delivers it to every subscribed endpoint and keeps trying when their server is down.

Explore outgoing webhooks
  • Retries + failed messages

    408, 429, 5xx and timeouts retry for up to 31 hours, then wait in Failed messages for you to resend.

  • Signatures + rotation

    Standard Webhooks headers any library verifies. During a rotation, requests carry both signatures.

  • Customer portal

    Embed a page where your customers add endpoints, see their deliveries and retry the failed ones.

Endpointorder.paidorder.refundeduser.created
Portalhooks.northwind.io✓ 200✓ 200✓ 204
api.acme-shop.com✓ 200✕ 503✓ 200
erp.globex.com✕ refused✕ refused✓ 200
billing.initech.dev✓ 200✓ 200✓ 200
crm.umbrella.co✓ 202✕ 429✓ 202
hooks.stark.io✓ 200✓ 200✕ 500
notify.wayne.app✓ 200✓ 200✓ 200

A buffer in front of your app

Incoming webhooks

Point Stripe or GitHub at Railhook instead of at your app. It checks the signature, answers them at once and forwards to you with the same retries.

Explore incoming webhooks
  • Signature verification

    Stripe, GitHub, Shopify, Slack, Twilio, SendGrid or any HMAC. Forged requests are refused and still logged.

  • Forward with retries

    If your app is down, the request waits in Railhook and is forwarded when it comes back.

  • Replay + Time Machine

    Resend a past time range to your app as new deliveries, for example after fixing a bug in your handler.

SourceSignatureForwarded toResult
Stripe✓ verifiedbilling.internal/stripe✓ 200
GitHub✓ verifiedci.internal/github✓ 200
Shopify✓ verifiedorders.internal/shopify✕ 503 · retry 1m
Unknown✕ invalid—✕ rejected
Twilio✓ verifiedsms.internal/twilio✓ 200
SendGrid✓ verifiedmail.internal/events✓ 202
Slack✓ verifiedops.internal/slack✓ 200

Delivery

Their server was down for an hour.
The webhook still arrived.

How delivery works
If the worker restarts, the delivery waits in PostgreSQL
Default schedule, outgoingchange it per endpoint
Attempt1234567
Waits—1m5m15m1h6h24h→ Failed messages
Since first try01m6m21m1h 21m7h 21m31h 21m

Retried: 408, 429, 5xx, timeouts, connection errors. Not retried: other 4xx, they go straight to Failed messages. Send an Idempotency-Key and a repeated call returns the event you already created.

Self-hosting

# one command: writes .env with generated secrets,
# gets a certificate and starts the stack
curl -fsSL https://railhook.io/install.sh | bash -s -- \
  --domain hooks.example.com --email ops@example.com

# day two
./railhook status
./railhook upgrade    # backs up first
./railhook backup

PostgreSQL and Redis in one Compose file

Runs on your server.

The self-hosted version is the whole product: every feature, no event limits, no licence key.

Deploy
Docker Compose or the Helm chart
Needs
Docker, about 4 GB of RAM
HTTPS
Caddy + Let’s Encrypt with --domain
Ops
Prometheus metrics, optional Grafana stack with alerts
Read the self-hosting guide

Start in our cloud,
or run it on your server.

Railhook Cloud: 10,000 events a month, 3 projects, 7 days of history. Self-hosted: everything, MIT.