HookGet עברית Start free

Documentation

The API is small on purpose. These are the pages that cover it, in the order most people need them.

In short

  • Start with the walkthrough: account, endpoint, first delivery.
  • Every dashboard action is an API call with the same permissions.
  • Signature verification is fifteen lines — the guide has it in full.
One event, every destination kind A published event fans out to every subscribed destination: an HTTPS endpoint receives a signed POST, a queue or bus receives a message with the signature as attributes, an object store receives one object per delivery, and a polling consumer pulls from a cursor instead of being pushed to. Retries, the timeline and metering are identical for all of them. One event publish once Fan-out filter · transform · sign HTTPS endpoint signed POST, three headers Queue or bus seven brokers, one endpoint field Object storage one object per delivery, S3-compatible Polling consumer GET /v1/poll/{id} — they pull
Every kind is an ordinary endpoint: same retries, same timeline, same metering, on every plan. The dashed arrow runs the other way on purpose — a polling destination is never pushed to; the consumer reads from a cursor when it likes.

API surface

Authentication is a bearer token: an API key for machines, a session for the dashboard.

EndpointWhat it does
POST /v1/eventsPublish an event. Answers 202 once it is stored. Optional attributes and metrics make it chart on a dashboard
POST /v1/events/batchPublish several; each item is judged on its own
GET /v1/eventsThe event log, filterable by type
GET /v1/events/{id}/attemptsThe delivery timeline for one event
POST /v1/events/{id}/replaySend an event again
POST /v1/events/replay-missingRepair a gap: re-queue events with no attempt
POST /v1/endpointsCreate a destination. The signing secret is returned once — as is the ed25519 private key, if you asked for signing_scheme: "ed25519"
PATCH /v1/endpoints/{id}Change the URL, the retry schedule, the filter, the transformation or the signing scheme
POST /v1/portal-linksMint a consumer portal grant. embed: true plus a brand returns an iframe snippet with your logo and colour; manage: true lets the holder move their destination, rotate their key and pause deliveries; consumer_id plus create: true lets them add endpoints of their own — and every later link for that consumer sees them
POST /v1/portal/endpointsCreate an endpoint from inside the portal, under a consumer grant. A URL, event types and a description — narrower than the operator surface, deliberately
GET /v1/poll/{id}A polling destination, read from a cursor — for a consumer with no public URL. Authenticated with a portal grant
POST /v1/endpoints/{id}/rotate-secretRotate with an overlap window
POST /v1/endpoints/{id}/recoverResume a disabled destination and replay its dead letters
GET /v1/endpoints/{id}/healthSuccess rate, latency percentiles, consecutive failures
POST /v1/sourcesCreate a verified inbound source
POST /ingest/{id}Where the third-party provider posts
GET /v1/dlq · POST /v1/dlq/replayInspect and drain dead letters
GET /v1/stats · GET /v1/usageVolumes and billable units
POST /v1/keysMint a scoped key. Never more powerful than the key that created it
/v1/membersTeam management
/v1/private-reposPrivate Repo: register a repository under a hash, report a checkpoint manifest, read history and machine health. Opaque ids and counts only — no path, no commit message, no code ever reaches these routes
/v1/ai-spendAI spend by model, feature tag, ledger or mapped person, and the remaining prepaid gateway balance. Read-only

Errors are RFC 9457 problem documents: a type, a title, a status and a readable detail. A resource that belongs to another tenant is reported as not found.

Event types the connectors emit

A pull connector reports what the provider reports: settled aggregates, never one row per call. The AI ones are worth naming because money and tokens are deliberately separate.

Event typeWhat it carries
llm.usage_reportedTokens for one settled (bucket, model): input, output, cached, reasoning, requests. No cost — summing a per-model cost column would multiply the bill
llm.cost_reportedThe money, on its own event. sum(cost_usd) is the bill
llm.credits_reportedRemaining prepaid balance on a unified-billing gateway. A level, not a flow — a balance that empties strands production silently

The ai-gateway source reads a unified-billing gateway’s reporting API, so spend that left the provider’s own ledger is still visible. Its events always declare provider: "ai-gateway" with the upstream vendor as upstream_provider: a customer running both ledgers can never have one request counted twice. Aggregates only — request logs contain prompts and are never read.

For agents

HookGet ships an MCP server — the same API behind 57 tools, so an assistant can publish an event, read a delivery timeline, diagnose an endpoint, read what AI cost by feature, or repair a gap. Operations that re-send real traffic require an explicit confirmation argument rather than a polite label.

Start delivering webhooks today

Point your webhooks at HookGet and watch the first delivery arrive, signed, in under a minute.

Create a free account Try the free webhook tester

10,000 deliveries a month free, no credit card. The free tier blocks rather than bills, so trying it cannot produce an invoice.