Free CLI
tier:free-cli Find every webhook bug in your codebase. Today.
- Languages
- JS · TS · Python · PHP · Go
- Frameworks
- 15
- Providers
- 24
- Output
- JSON · SARIF · terminal
- License
- Apache 2.0
The scanner laser-focused on webhook signature verification. Point it at your repo and it finds every handler a forged payload could slip past — JS, TS, Python, PHP, and Go. Local, deterministic, zero-network.
No account needed for the CLI — npx hookwarden scan runs fully offline. The hosted dashboard is launching soon.
24 providers · 30 rule classes · 15 frameworks · 5 languages · 5 install surfaces — one CLI that runs anywhere.
hookwarden labels every webhook handler in your codebase from the source alone, reporting only what it can prove. The third state — manual-review — is how it avoids guessing: anything it can't prove goes to a person instead of failing your build.
The signature is never checked, compared with == instead of a timing-safe equal, or computed over an already-parsed body. Fix before you ship — and hookwarden fix can rewrite most of them for you.
Reachable and correct — a valid signature check sits on the handler's path. Nothing to fix.
Can't be proven safe or unsafe from the source alone — like a handler inside a middleware chain the analyzer couldn't fully unroll. Flagged for a human, never guessed.
scan finds every handler a forged payload could slip past; fix rewrites the unsafe ones with each provider's correct, timing-safe verification. Dry-run by default — --write applies.
Watch the AST passes run against a known-broken Stripe handler — same rule pack, same 3-state verdict the CLI ships. Toggle to the correct version to see a verified short-circuit.
app.post('/webhooks/stripe', async (req, res) => { const sig = req.headers['stripe-signature']; const event = JSON.parse(req.body); if (event.type === 'checkout.session.completed') { await fulfillOrder(event.data.object); } res.json({ received: true }); });
The handler captures the stripe-signature header but never
verifies it. No stripe.webhooks.constructEvent call is reachable
within 4 hops and no manual HMAC path was detected — a forged payload would reach
fulfillOrder.
See the Correct (Stripe) tab for a full working handler.
Now run it on your whole codebase.
$ npx hookwarden scan The CLI is free and local. The platform takes the same finding the rest of the way — watched in production, rotated automatically, handed to your auditor. No re-keying, no re-explaining.
A dual-secret window on every rotation — verified against a live delivery before the old secret is retired. Delivery never drops.
Providers without a rotation API get a guided, gated runbook — every step signed.
Append-only and hash-chained — every row links to the one before it.
Every inbound delivery scored in real time — signature, timestamp, and sequence integrity — across all your providers.
The same tamper-evident chain — now tagged with the EU AI Act Annex III high-risk classification, alongside your SOC 2 and ISO 27001 mappings. Real, KMS-signed, offline-verifiable.
The CLI catches every webhook bug today, locally, for free. The SaaS keeps watch tomorrow.
tier:free-cli Find every webhook bug in your codebase. Today.
tier:solo Continuous monitoring for one small team.
Hosted tier launching soon
tier:team or $25 / dev / month — whichever is higher
Monitoring + rotation orchestration + SOC2 evidence pack.
Hosted tier launching soon
tier:enterprise Monitoring + rotation orchestration + custom rules + on-prem.
All paid tiers · 30-day free trial · annual prepay ~15% off · EU-hosted (Frankfurt) · cancel anytime
Start with the open-source CLI. Upgrade when compliance comes knocking.
$ npx hookwarden scan