Open source

Webhook Workbench

Open source · Webhook debugging in Go

A private, self-hosted workbench to capture, inspect, verify and safely replay webhooks — one dependency-free Go binary with the UI built in.

Webhook Workbench preview

Problem

Debugging webhooks often means sending real payloads to a third-party inspection service.

Solution

A self-hosted Go binary that captures, verifies and safely replays webhooks, redacting secrets before storage.

Built in

Tests cover redaction, signature checks, replay and SSRF defences. Checksummed release binaries; live sandbox.

Overview

Webhook Workbench captures incoming webhooks on any channel and shows each request's decoded payload, redacted headers and a ready-to-run cURL command. It ships as a single Go binary built on the standard library alone, with the browser interface embedded, and listens only on localhost by default.

Signatures are verified against the exact captured body for GitHub, Stripe (with its five-minute receipt window) and generic HMAC-SHA-256 profiles; the secret is used once and never stored. Captured requests can be replayed to an endpoint of your choice, but conservatively: private, loopback and non-HTTP targets are rejected, DNS is re-checked on connect, redirects are limited, and authorization, cookie and hop-by-hop headers are stripped.

It keeps a bounded event history in a local JSON snapshot, preserves binary bodies as base64 and exposes a health probe. The Docker setup runs as a non-root user with dropped capabilities and a read-only root filesystem, and the tests cover redaction, signature verification, replay behaviour and SSRF defences.

What it does

  • Captures any HTTP method at /inbox/{channel} and shows traffic live
  • Verifies GitHub, Stripe and generic HMAC-SHA-256 signatures
  • Replays captured requests safely, with SSRF protection
  • Redacts secrets before storage; optional bearer-token auth

What's next

Hiring for a full-stack, Python or AI role — or need something like this built? Let's talk.

I'm available immediately — on-site or hybrid in Moscow, or remote; full-time or contract. I reply within 48 hours — faster on Telegram.

Get in touch TelegramDownload CV

Alhassan Alfarran.

© 2026 · Designed and built by me with Next.js, Tailwind and Framer Motion.

My local time: · Moscow

Notes
How this site is built

Stack

Next.js (App Router) and React, styled with Tailwind CSS and animated with Framer Motion. The contact form sends email through Resend; the site is hosted on Vercel.

Three languages, one layout

English, Russian and Arabic each have their own address (/en, /ru, /ar) and share one set of components. The layout uses logical CSS properties (start/end instead of left/right), so Arabic mirrors right to left without separate styles. The server sends every page with its language and text direction already set, so nothing flips after loading, and the Arabic font is only downloaded when Arabic text is on screen.

Performance and accessibility

Sections below the first screen skip rendering until you scroll near them, and the quick menu loads on first use. Everything works from the keyboard, with a skip link and visible focus, and animations switch off when your system asks for reduced motion.

Source code on GitHub