Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,536Letters: 14Defects: 1,322counted 4 min ago
teppi

Server definition

Hash
sha256:5b55c4851cc4b5410cd3549c79f32acd8c309043f1e3a3fc93fada1f0000c76b
What it is
What a remote MCP server returned when asked what it offers: 7 tools

The blob, as servednamed by its sha256

{ "instructions": "Hookden gives you disposable public HTTPS endpoints that capture every request sent to them. Typical flow: create_bin → give the capture_url to a webhook sender (Stripe, GitHub, a cron, your own code) → wait_for_capture (blocks up to 45s) or list_captures → get_capture for full headers/body. To try the loop with no external sender, send_test_webhook seeds a realistic labeled sample into a bin. set_response configures what a bin replies (status/content-type/body/headers/delay; {{…}} templates rendered from the incoming request let a bin pass Slack/Zoom/Meta/Strava verification handshakes with zero code). verify_signature checks a webhook signature against a secret (25 provider-exact schemes + generic HMAC — incl. ECDSA/RSA/MD5 ones generic HMAC tools cannot do) with no bin needed. Bins need no auth and keep captures ~24h. Humans can watch the same bin live at the inspect_url. REST equivalent of everything here: see /openapi.json on the same origin.", "tools": [ { "description": "Create a new webhook capture bin. Returns a public capture_url — point any webhook (Stripe, GitHub, Slack, your own service…) at it and every request sent there (any method, any subpath, headers + raw body) is stored. Then read what arrived with list_captures, get_capture, or wait_for_capture. Anonymous bins keep requests ~24h. No auth needed.", "inputSchema": { "additionalProperties": false, "properties": {}, "type": "object" }, "name": "create_bin", "outputSchema": null }, { "description": "Get one captured request in full: method, path, query, every header, and the body. Binary bodies are returned base64-encoded (up to 8KB, with a URL for the raw bytes).", "inputSchema": { "additionalProperties": false, "properties": { "bin": { "description": "bin id or slug", "type": "string" }, "id": { "description": "capture id from list_captures / wait_for_capture", "type": "integer" } }, "required": [ "bin", "id" ], "type": "object" }, "name": "get_capture", "outputSchema": null }, { "description": "List requests captured by a bin, oldest first. Compact summaries (id, method, path, time, content-type, body size, signature status). Use get_capture for full headers/body. Pass `after` (a capture id) to only see newer captures.", "inputSchema": { "additionalProperties": false, "properties": { "after": { "description": "only captures with id greater than this (default 0)", "type": "integer" }, "bin": { "description": "bin id (or custom slug) from create_bin", "type": "string" }, "limit": { "description": "max results, 1-50 (default 20)", "type": "integer" } }, "required": [ "bin" ], "type": "object" }, "name": "list_captures", "outputSchema": null }, { "description": "Simulate a webhook delivery into a bin — no external sender or HTTP client needed. Seeds one realistic, clearly-labeled sample capture (default: a GitHub push event) and returns it in full, so you can exercise the whole loop (create_bin → send_test_webhook → list_captures / get_capture) entirely from MCP. Pass `example` to pick a provider payload from the /examples library (e.g. \"stripe-payment-intent-succeeded\", \"slack-event-callback\", \"shopify-order-created\"). Sample captures are marked as simulated and never count as real webhook traffic.", "inputSchema": { "additionalProperties": false, "properties": { "bin": { "description": "bin id (or custom slug) from create_bin", "type": "string" }, "example": { "description": "optional example payload slug from /examples (default: a GitHub push event)", "type": "string" } }, "required": [ "bin" ], "type": "object" }, "name": "send_test_webhook", "outputSchema": null }, { "description": "Configure what a bin replies to webhook senders: HTTP status, content-type, body, custom response headers, optional delay. Body and header values support {{…}} templates rendered per-request from the INCOMING delivery — {{body.challenge}}, {{query.hub.challenge}}, {{header.x-hook-secret}}, {{hmac_sha256 body.plainToken YOUR_SECRET}} — so a bin can pass provider verification handshakes with zero code: Slack URL verification (body {{body.challenge}}), Zoom CRC (JSON with the hmac_sha256 helper), Meta/WhatsApp GET echo (text/plain {{query.hub.challenge}}), Strava (JSON {\"hub.challenge\":\"{{query.hub.challenge}}\"}), Asana (response header X-Hook-Secret: {{header.x-hook-secret}}). Only the fields you pass change; everything else keeps its current value. Works on bins created via create_bin by this same client; the incoming request is still captured in full either way.", "inputSchema": { "additionalProperties": false, "properties": { "bin": { "description": "bin id (or custom slug) from create_bin", "type": "string" }, "body": { "description": "response body, max 10000 chars; {{…}} templates allowed", "type": "string" }, "content_type": { "description": "Content-Type of the response (e.g. application/json, text/plain)", "type": "string" }, "delay_ms": { "description": "artificial response delay in milliseconds, 0-10000 (for testing sender timeouts/retries)", "type": "integer" }, "headers": { "additionalProperties": { "type": "string" }, "description": "custom response headers as name→value (max 10; values may use {{…}} templates). Pass {} to clear. Hop-by-hop/security headers (set-cookie, location, strict-transport-security…) are rejected.", "type": "object" }, "status": { "description": "HTTP status to respond with, 100-599 (bins default to 200)", "type": "integer" } }, "required": [ "bin" ], "type": "object" }, "name": "set_response", "outputSchema": null }, { "description": "Verify a webhook signature against a secret — 25 provider-exact schemes plus a generic HMAC mode, the same engine that computes ✓/✗ badges on captures. Covers HMAC-SHA256 (GitHub, Stripe, Svix/Standard Webhooks, Shopify-style base64, URL-signing Square/HubSpot/Trello…), ECDSA (SendGrid), RSA (Kick) and HMAC-MD5 (Patreon). Pass the scheme, the secret, the delivery's headers, and the BYTE-EXACT raw body (body_base64 for binary). The secret is used only for this one in-memory computation — never stored or logged. No bin needed. If verification fails, the #1 cause is a re-serialized body: point the real webhook at a capture bin (create_bin) to get the true raw bytes first.", "inputSchema": { "additionalProperties": false, "properties": { "body": { "description": "raw request body, byte-exact as the provider sent it (not re-serialized!)", "type": "string" }, "body_base64": { "description": "alternative to `body` for binary payloads: base64 of the raw body bytes", "type": "string" }, "headers": { "additionalProperties": { "type": "string" }, "description": "the delivery's HTTP headers — at least the signature/timestamp headers; names are case-insensitive", "type": "object" }, "method": { "description": "HTTP method of the delivery (hubspot v3 signs it; default POST)", "type": "string" }, "scheme": { "description": "signature scheme (usually the provider name); \"hmac\" = generic HMAC over the raw body", "enum": [ "github", "stripe", "svix", "calendly", "mailchimp", "mux", "workos", "paddle", "notion", "patreon", "intercom", "zendesk", "trello", "webflow", "square", "hubspot", "twitch", "frameio", "buildkite", "airtable", "mailgun", "adyen", "sendgrid", "kick", "hmac" ], "type": "string" }, "secret": { "description": "signing secret or key exactly as the provider shows it (sendgrid/kick: the PUBLIC verification key)", "type": "string" }, "signature_header": { "description": "scheme \"hmac\" only: which header carries the signature (default x-signature)", "type": "string" }, "url": { "description": "full delivery URL — REQUIRED for square, hubspot and trello (the URL is part of the signed string)", "type": "string" } }, "required": [ "scheme", "secret" ], "type": "object" }, "name": "verify_signature", "outputSchema": null }, { "description": "Block until the next request arrives at a bin (or a timeout passes), then return it in full. Ideal flow: create_bin → configure the webhook sender → trigger it → wait_for_capture. If `after_id` is omitted, waits for the next capture after \"now\". Returns timed_out:true instead of erroring when nothing arrives.", "inputSchema": { "additionalProperties": false, "properties": { "after_id": { "description": "return the first capture with id greater than this; default = latest id at call time", "type": "integer" }, "bin": { "description": "bin id or slug", "type": "string" }, "timeout_seconds": { "description": "1-45 seconds to wait (default 20)", "type": "integer" } }, "required": [ "bin" ], "type": "object" }, "name": "wait_for_capture", "outputSchema": null } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:5b55c4851cc4b5410cd3549c79f32acd8c309043f1e3a3fc93fada1f0000c76b | sha256sum