A native macOS webhook debugger. One stable URL per endpoint for Stripe, Polar, GitHub, Shopify and Slack. Every event with headers and body, a plain-English verdict when a signature fails, forwarding to localhost, and replay re-signed with a fresh timestamp.
Hi Product Hunt, I'm Spencer, and I built WebhookMon because every webhook
integration I've written started the same way: a tunnel, a handler that
returns 400, and twenty minutes of guessing whether the secret was wrong,
the timestamp was stale, or I was hashing the wrong bytes.
WebhookMon gives each endpoint a public URL you paste into Stripe, Polar,
GitHub, Shopify or Slack once. Events show up on your Mac with headers, body
and the response your local server gave. The Signature tab checks each one
the way that provider actually signs it, and says which thing is wrong:
"the secret is wrong", "timestamp is 12 minutes old, outside the 5-minute
tolerance", "header is malformed". Add the secret later and earlier events
are re-verified on the spot.
Replay is the part I use most. Send an event again byte for byte, edit the
body first, point it at a different target, or re-sign it with the current
timestamp so Stripe, Polar and Slack stop rejecting it as stale. Every
delivery keeps its status, timing and response, and you can pick two and
diff them to see what changed between the 400 and the 200.
About the relay, since you'll ask: it's a small Cloudflare Worker. Before
it stores anything it seals the event with HPKE to your Mac's public key,
so it holds ciphertext it cannot open. Events are deleted the moment your
Mac acknowledges them, or after 24 hours. It keeps your email, device keys,
hashed tokens and endpoint names, nothing else. The relay URL is yours to
keep; no tunnel process, and events queue while your laptop is asleep.
Signing secrets never leave your Keychain.