Developer tools decision

HookSense

Build: a competent engineer can reproduce the core webhook capture/inspect/replay workflow and reasonable retention and verification in a few weeks; HookSense's durable moats are limited, and open-source prior art exists (webhook.site).

Visit website

Built by Ozer SUBASI, who ships 4 products in this index

You pay

$29/mo

$348/yr

Read off the official pricing page.

You’d pay instead

$100one-off120 h to build

$60/mo6 h/mo upkeep

On cash alone, building overtakes the subscription at 3 seats.

No open-source build does this yet

Nothing published replaces this one, so a replacement starts from an empty file. Here is what it would have to cover.

What a replacement has to do

  • Receive HTTP POST to stable URL → persist payload and metadata → show live arrival in UI via WebSocket → verify provider signature (HMAC) → allow replay to arbitrary URL and to localhost via forwarding

What it still won’t have

  • Agent-native MCP server and wait_for_callback primitives out of the box
  • Early-access team features (multi-seat, custom domains, SLA/priority support)
  • Polish around provider auto-detection and many built-in provider fixtures
  • Guaranteed retention tiers, uptime SLA, and built-in encrypted-at-rest policy by vendor

What remains hard

  • Product polish and ongoing maintenance
Read the build prompt

First-year cost

Keep paying

Paying is—cheaper in year one.

On cash alone, building overtakes the subscription at 3 seats.

Paid seatsseats

Money you would actually spend

Keep paying
—

Subscription price × seats × 12

Build it
—

AI build —APIs + hosting —

Time you would spend

—

—

What you would spend

What we assumed

The verdict above measures whether you could build it. This one is only about money.

Runnable build prompt

Not run yet
Build a minimal self-hosted webhook inspector using Node.js (Express) + PostgreSQL + Redis + React; deploy via Docker to a single VPS. In scope: (1) endpoint minting (stable /w/:slug URLs) and HTTP capture, (2) store request metadata and body with retention policy in Postgres, (3) timing-safe HMAC signature verification for Stripe/GitHub/Shopify and configurable secrets, (4) WebSocket live updates to the React UI, (5) replay/forward worker that can resend payloads to arbitrary URLs and a CLI command (npx hooksense listen) that forwards to localhost, (6) basic search/filter UI, and (7) encrypted-at-rest for payload bodies. Out of scope: multi-tenant billing, SLA/priority support, custom domains, advanced analytics dashboards, and a production MCP implementation beyond a simple WebSocket-based wait_for_callback emulation. Include error handling, retries for replay, retention enforcement, automated tests for capture/verify/replay, and Docker Compose for local/dev and a README with deployment steps.
How we checked2 sources · 3/3 runs agreed · evidence score 60

How the score was reached

  • Partly verdict base52
  • 2 cited sources+1
  • Price verified on pricing page+3
  • 3/3 assessment runs agreed+4
  • Evidence score60

The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time - so the same evidence always produces the same number.

How scoring works →

Cited sources · 2

Every page the run actually retrieved.

Integrity checks

What held up, and what did not.

✓ Price read off the page✓ 3 independent runs, one answer✓ Citations limited to fetched pages! 1 moat recorded