Skill: Webhook secure intake

FREE with proof-of-work · or $0.006 in USDC · POST /api/skill/webhook-intake

The production ingest path for every incoming webhook: verify the provider signature (GitHub / Stripe / Shopify / Slack, constant-time, replay-window enforced), schema-validate the now-trusted body against the provider envelope, fingerprint the raw bytes for redelivery dedup, normalize the event timestamp to UTC + epoch, and redact PII before anything hits a log. Send POST /api/skill/webhook-intake with the required fields rawBody, provider, secret and signature and pay $0.006 per call over x402 or MPP, or call it free by solving a proof-of-work challenge. It returns a JSON object with pack, args, steps and summary.

Five pure-CPU tools - the accept-or-reject gate, run on every event. Webhook secure intake skill pack: one x402 payment runs 5 underlying tools (webhook-verify, json-validate, hash, time-convert, redact); partial-success per step.

Category: Skill packs · Tags: skill-pack workflow webhook-intake · Pack overview

TRY IN PLAYGROUND →

Parameters

NameTypeRequiredDescription
rawBodystringyesthe raw webhook body exactly as received on the wire (signatures are over the raw bytes)
providerstringyeswhich provider signed the webhook: github | stripe | shopify | slack
secretstringyesthe webhook signing secret from the provider dashboard (never echoed back) Also accepted as key, password, passphrase.
signaturestringyesthe signature header value, with or without its scheme prefix (sha256= / v0= / t=...,v1=...)
timestampstringnothe provider timestamp header - required for stripe/slack replay protection (stripe's may ride in the signature's t= element)

Example request

curl -i -X POST https://agent402.tools/api/skill/webhook-intake \
  -H "Content-Type: application/json" \
  -d '{"rawBody":"{\"ref\":\"refs/heads/main\",\"before\":\"6113728f27ae82c7b1a177c8d03f9e96e0adf246\",\"after\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"repository\":{\"full_name\":\"acme/checkout-service\"},\"pusher\":{\"name\":\"alice\",\"email\":\"alice@example.com\"},\"head_commit\":{\"id\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"message\":\"fix: retry payment capture on 5xx\",\"timestamp\":\"2026-07-01T15:04:05Z\"}}","provider":"github","secret":"gh_hook_secret_demo_only","signature":"sha256=45f74caa8f537323fd4fa022357ebc620cbcfb28a6dcd65b0f1da3646edf5c4a"}'

Without payment this returns HTTP 402 Payment Required with the exact price for skill-webhook-intake; any x402 v2 or MPP client pays it and retries.

Example response

{
  "pack": "webhook-intake",
  "args": {
    "rawBody": "{\"ref\":\"refs/heads/main\",\"before\":\"6113728f27ae82c7b1a177c8d03f9e96e0adf246\",\"after\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"repository\":{\"full_name\":\"acme/checkout-service\"},\"pusher\":{\"name\":\"alice\",\"email\":\"alice@example.com\"},\"head_commit\":{\"id\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"message\":\"fix: retry payment capture on 5xx\",\"timestamp\":\"2026-07-01T15:04:05Z\"}}",
    "provider": "github",
    "secret": "gh_hook_secret_demo_only",
    "signature": "sha256=45f74caa8f537323fd4fa022357ebc620cbcfb28a6dcd65b0f1da3646edf5c4a"
  },
  "steps": [
    {
      "slug": "webhook-verify",
      "ok": true,
      "result": {}
    },
    {
      "slug": "json-validate",
      "ok": true,
      "result": {}
    },
    {
      "slug": "hash",
      "ok": true,
      "result": {}
    },
    {
      "slug": "time-convert",
      "ok": true,
      "result": {}
    },
    {
      "slug": "redact",
      "ok": true,
      "result": {}
    }
  ],
  "summary": "5/5 steps succeeded"
}
FieldTypeAlways presentIn the example
packstringyeswebhook-intake
argsobjectyes5 fields: rawBody, provider, secret, signature, timestamp
stepsarray of objectsyes5 items in the example
summarystringyes5/5 steps succeeded

From an MCP client

catalog.call {
  "slug": "skill-webhook-intake",
  "params": {
    "rawBody": "{\"ref\":\"refs/heads/main\",\"before\":\"6113728f27ae82c7b1a177c8d03f9e96e0adf246\",\"after\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"repository\":{\"full_name\":\"acme/checkout-service\"},\"pusher\":{\"name\":\"alice\",\"email\":\"alice@example.com\"},\"head_commit\":{\"id\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"message\":\"fix: retry payment capture on 5xx\",\"timestamp\":\"2026-07-01T15:04:05Z\"}}",
    "provider": "github",
    "secret": "gh_hook_secret_demo_only",
    "signature": "sha256=45f74caa8f537323fd4fa022357ebc620cbcfb28a6dcd65b0f1da3646edf5c4a"
  }
}

On the hosted connector at https://agent402.tools/mcp, catalog.call runs skill-webhook-intake free (rate-limited, no wallet). Local install: npx -y agent402-mcp.

Errors and behavior

Paid call (JavaScript agent)

import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);

const res = await payFetch("https://agent402.tools/api/skill/webhook-intake", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({
    "rawBody": "{\"ref\":\"refs/heads/main\",\"before\":\"6113728f27ae82c7b1a177c8d03f9e96e0adf246\",\"after\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"repository\":{\"full_name\":\"acme/checkout-service\"},\"pusher\":{\"name\":\"alice\",\"email\":\"alice@example.com\"},\"head_commit\":{\"id\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"message\":\"fix: retry payment capture on 5xx\",\"timestamp\":\"2026-07-01T15:04:05Z\"}}",
    "provider": "github",
    "secret": "gh_hook_secret_demo_only",
    "signature": "sha256=45f74caa8f537323fd4fa022357ebc620cbcfb28a6dcd65b0f1da3646edf5c4a"
  }),
});

No wallet? Pay with compute

Fetch a challenge, solve the sha256 puzzle (16 leading zero bits, a fraction of a second of CPU), and resend with the X-Pow-Solution header:

import { createHash } from "node:crypto";
const lz = (b) => { let t = 0; for (const x of b) { if (!x) { t += 8; continue; } t += Math.clz32(x) - 24; break; } return t; };
const c = await (await fetch("https://agent402.tools/api/pow/challenge?slug=skill-webhook-intake")).json();
let n = 0;
while (lz(createHash("sha256").update(c.challenge + ":" + n).digest()) < c.difficulty) n++;
await fetch("https://agent402.tools/api/skill/webhook-intake", { method: "POST", headers: { "X-Pow-Solution": c.token + ":" + n, "Content-Type": "application/json" }, body: JSON.stringify({"rawBody":"{\"ref\":\"refs/heads/main\",\"before\":\"6113728f27ae82c7b1a177c8d03f9e96e0adf246\",\"after\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"repository\":{\"full_name\":\"acme/checkout-service\"},\"pusher\":{\"name\":\"alice\",\"email\":\"alice@example.com\"},\"head_commit\":{\"id\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"message\":\"fix: retry payment capture on 5xx\",\"timestamp\":\"2026-07-01T15:04:05Z\"}}","provider":"github","secret":"gh_hook_secret_demo_only","signature":"sha256=45f74caa8f537323fd4fa022357ebc620cbcfb28a6dcd65b0f1da3646edf5c4a"}) });

Related tools

Skill: Convert anything to markdown

$0.026 · POST /api/skill/any-to-markdown

Convert anything at a URL - HTML, PDF, or an image - to clean markdown. The 'I have a URL but it might be any content-ty…

Skill: API health check

$0.005 · POST /api/skill/api-health

Is this API endpoint healthy? Liveness check, response headers, and TLS certificate status in one pass. API health check…

Skill: API investigation

$0.017 · POST /api/skill/api-investigation

Point at an unknown API endpoint and figure out how to use it: auth scheme, content type, version, rate limits, OpenAPI/…

Skill: Article digest

$0.09 · POST /api/skill/article-digest

Quick research brief on any topic - web search results plus an AI-generated answer in one pass. Article digest skill pac…

Skill: Brand protection

$0.018 · POST /api/skill/brand-protection

Is this domain legitimate? WHOIS age, DNS resolution, scam/phishing search results, and HTTP headers for a quick trust a…

Skill: Cheapest rail right now

$0.009 · POST /api/skill/cheapest-rail

Where should an agent transact this minute? Live gas on Ethereum + every major L2 side by side, Base gas tiers, a fee es…