Providers

Fluent in your provider's dialect.

Every provider does webhooks differently: where the event type lives, which header carries the signature, whether subscribing demands a challenge handshake. WebhookVault knows the dialects, so pick a provider on an endpoint and the vault reads its deliveries the way that provider writes them.

Stripetype · Stripe-Signature
GitHubX-GitHub-Event · HMAC-SHA256
GitLabX-Gitlab-Event · secret token
BitbucketX-Event-Key · HMAC
ShopifyX-Shopify-Topic · HMAC-SHA256
WooCommerceX-WC-Webhook-Topic · HMAC
Slackevent.type · handshake
DiscordEd25519 · PING handshake
Telegramsecret-token header
TwilioX-Twilio-Signature
SendGridsigned event webhook
Mailgunevent-data.event
PostmarkRecordType
Resendsvix signature
PayPalevent_type · transmission sig
SquareHMAC-SHA256 signature
AdyenHMAC notifications
PaddlePaddle-Signature
Lemon SqueezyX-Event-Name · X-Signature
GoCardlessWebhook-Signature
PaystackHMAC-SHA512
PayFastITN + validate-back
Ozowresponse hash check
Yocostandard webhooks
Zoomx-zm-signature · handshake
Clerksvix signature

…and 60+ more, named and selectable: Azure DevOps, Gitea, Jenkins, CircleCI, Buildkite, Vercel, Netlify, Render, Railway, Heroku, Cloudflare, Sentry, PagerDuty, Datadog, Grafana, Opsgenie, Linear, Jira, Trello, Asana, Notion, Airtable, Monday.com, Typeform, Calendly, HubSpot, Intercom, Zendesk, Salesforce, DocuSign, Auth0, Okta, WorkOS, FusionAuth, Mailchimp, MailerSend, SparkPost, Klaviyo, Customer.io, BigCommerce, Squarespace, Wix, Magento, Chargebee, Recurly, Braintree, Wise, Coinbase Commerce, Razorpay, Mollie, Flutterwave, Peach Payments, Stitch, Twitch, Stripe Connect, OpenAI, Replicate, ElevenLabs, Dropbox, Microsoft Graph, Meta, Strava. Anything else runs as a generic endpoint with manual HMAC verification.

What a provider preset does

Pick the sender, get its grammar

Set once per endpoint, applied to every delivery, history included.

Event-aware rows

The explorer labels every capture with the provider's own event name, invoice.paid, orders/create, push, read from wherever that provider puts it: a body field for Stripe and PayPal, a header for GitHub and Shopify. Search and filters speak the same names.

Subscription handshakes, answered

Slack's url_verification, Zoom's plainToken, Dropbox's echo, Microsoft Graph's validationToken: providers that demand proof of ownership before they send get their handshake answered by the endpoint itself, so registration succeeds without you writing a temporary responder.

Signature verdicts

Add your signing secret and every capture carries a verified or unsigned verdict in the provider's own scheme, Stripe's timestamped HMAC, GitHub's X-Hub-Signature-256, Discord's Ed25519. How verification works →

Your provider is on the wall.

Point it at the vault and watch its dialect come through labeled. Free tier, no card.