Skill: Webhook secure intake
POST /api/skill/webhook-intakeThe production ingest path for every incoming webhook: verify the provider signature (GitHub / Stripe / Shopify / Slack, constant-time, replay-window enforced), schema-validate the now-trusted body against the provider envelope, fingerprint the raw bytes for redelivery dedup, normalize the event timestamp to UTC + epoch, and redact PII before anything hits a log. Send POST /api/skill/webhook-intake with the required fields rawBody, provider, secret and signature and pay $0.006 per call over x402 or MPP, or call it free by solving a proof-of-work challenge. It returns a JSON object with pack, args, steps and summary.
Five pure-CPU tools - the accept-or-reject gate, run on every event. Webhook secure intake skill pack: one x402 payment runs 5 underlying tools (webhook-verify, json-validate, hash, time-convert, redact); partial-success per step.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
rawBody | string | yes | the raw webhook body exactly as received on the wire (signatures are over the raw bytes) |
provider | string | yes | which provider signed the webhook: github | stripe | shopify | slack |
secret | string | yes | the webhook signing secret from the provider dashboard (never echoed back) Also accepted as key, password, passphrase. |
signature | string | yes | the signature header value, with or without its scheme prefix (sha256= / v0= / t=...,v1=...) |
timestamp | string | no | the provider timestamp header - required for stripe/slack replay protection (stripe's may ride in the signature's t= element) |
Example request
curl -i -X POST https://agent402.tools/api/skill/webhook-intake \
-H "Content-Type: application/json" \
-d '{"rawBody":"{\"ref\":\"refs/heads/main\",\"before\":\"6113728f27ae82c7b1a177c8d03f9e96e0adf246\",\"after\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"repository\":{\"full_name\":\"acme/checkout-service\"},\"pusher\":{\"name\":\"alice\",\"email\":\"alice@example.com\"},\"head_commit\":{\"id\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"message\":\"fix: retry payment capture on 5xx\",\"timestamp\":\"2026-07-01T15:04:05Z\"}}","provider":"github","secret":"gh_hook_secret_demo_only","signature":"sha256=45f74caa8f537323fd4fa022357ebc620cbcfb28a6dcd65b0f1da3646edf5c4a"}'
Without payment this returns HTTP 402 Payment Required with the exact price for skill-webhook-intake; any x402 v2 or MPP client pays it and retries.
Example response
{
"pack": "webhook-intake",
"args": {
"rawBody": "{\"ref\":\"refs/heads/main\",\"before\":\"6113728f27ae82c7b1a177c8d03f9e96e0adf246\",\"after\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"repository\":{\"full_name\":\"acme/checkout-service\"},\"pusher\":{\"name\":\"alice\",\"email\":\"alice@example.com\"},\"head_commit\":{\"id\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"message\":\"fix: retry payment capture on 5xx\",\"timestamp\":\"2026-07-01T15:04:05Z\"}}",
"provider": "github",
"secret": "gh_hook_secret_demo_only",
"signature": "sha256=45f74caa8f537323fd4fa022357ebc620cbcfb28a6dcd65b0f1da3646edf5c4a"
},
"steps": [
{
"slug": "webhook-verify",
"ok": true,
"result": {}
},
{
"slug": "json-validate",
"ok": true,
"result": {}
},
{
"slug": "hash",
"ok": true,
"result": {}
},
{
"slug": "time-convert",
"ok": true,
"result": {}
},
{
"slug": "redact",
"ok": true,
"result": {}
}
],
"summary": "5/5 steps succeeded"
}
| Field | Type | Always present | In the example |
|---|---|---|---|
pack | string | yes | webhook-intake |
args | object | yes | 5 fields: rawBody, provider, secret, signature, timestamp |
steps | array of objects | yes | 5 items in the example |
summary | string | yes | 5/5 steps succeeded |
From an MCP client
catalog.call {
"slug": "skill-webhook-intake",
"params": {
"rawBody": "{\"ref\":\"refs/heads/main\",\"before\":\"6113728f27ae82c7b1a177c8d03f9e96e0adf246\",\"after\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"repository\":{\"full_name\":\"acme/checkout-service\"},\"pusher\":{\"name\":\"alice\",\"email\":\"alice@example.com\"},\"head_commit\":{\"id\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"message\":\"fix: retry payment capture on 5xx\",\"timestamp\":\"2026-07-01T15:04:05Z\"}}",
"provider": "github",
"secret": "gh_hook_secret_demo_only",
"signature": "sha256=45f74caa8f537323fd4fa022357ebc620cbcfb28a6dcd65b0f1da3646edf5c4a"
}
}
On the hosted connector at https://agent402.tools/mcp, catalog.call runs skill-webhook-intake free (rate-limited, no wallet). Local install: npx -y agent402-mcp.
Errors and behavior
- Arguments left out fall back to the pack's own defaults. Each step reports on its own; the call succeeds when at least one step does, and a run where every step fails is refused (400 when the input caused it, 502 otherwise).
- A paid call that ends in any status of 400 or above is not charged over x402, MPP or a prepaid credits key: settlement is cancelled when the tool fails. The exception is a Tempo push credential, a transfer the buyer sent before the call: it settles before the tool runs, so if the tool then fails the payment is recorded as a refund owed to the paying wallet.
- Free tier: no outbound network call leaves the server for this tool, so proof-of-work (16 leading zero bits of sha256) pays for it.
- A
GETorHEADto /api/skill/webhook-intake returns the same 402 quote, so the price can be read without a body. - An
Idempotency-Keyheader makes a retried paid call replay the first 200 instead of charging again (an answer larger than 1 MB is not replayed).
Paid call (JavaScript agent)
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);
const res = await payFetch("https://agent402.tools/api/skill/webhook-intake", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
"rawBody": "{\"ref\":\"refs/heads/main\",\"before\":\"6113728f27ae82c7b1a177c8d03f9e96e0adf246\",\"after\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"repository\":{\"full_name\":\"acme/checkout-service\"},\"pusher\":{\"name\":\"alice\",\"email\":\"alice@example.com\"},\"head_commit\":{\"id\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"message\":\"fix: retry payment capture on 5xx\",\"timestamp\":\"2026-07-01T15:04:05Z\"}}",
"provider": "github",
"secret": "gh_hook_secret_demo_only",
"signature": "sha256=45f74caa8f537323fd4fa022357ebc620cbcfb28a6dcd65b0f1da3646edf5c4a"
}),
});
No wallet? Pay with compute
Fetch a challenge, solve the sha256 puzzle (16 leading zero bits, a fraction of a second of CPU), and resend with the X-Pow-Solution header:
import { createHash } from "node:crypto";
const lz = (b) => { let t = 0; for (const x of b) { if (!x) { t += 8; continue; } t += Math.clz32(x) - 24; break; } return t; };
const c = await (await fetch("https://agent402.tools/api/pow/challenge?slug=skill-webhook-intake")).json();
let n = 0;
while (lz(createHash("sha256").update(c.challenge + ":" + n).digest()) < c.difficulty) n++;
await fetch("https://agent402.tools/api/skill/webhook-intake", { method: "POST", headers: { "X-Pow-Solution": c.token + ":" + n, "Content-Type": "application/json" }, body: JSON.stringify({"rawBody":"{\"ref\":\"refs/heads/main\",\"before\":\"6113728f27ae82c7b1a177c8d03f9e96e0adf246\",\"after\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"repository\":{\"full_name\":\"acme/checkout-service\"},\"pusher\":{\"name\":\"alice\",\"email\":\"alice@example.com\"},\"head_commit\":{\"id\":\"d6fde92930d4715a2b49857d24b940956b26d2d3\",\"message\":\"fix: retry payment capture on 5xx\",\"timestamp\":\"2026-07-01T15:04:05Z\"}}","provider":"github","secret":"gh_hook_secret_demo_only","signature":"sha256=45f74caa8f537323fd4fa022357ebc620cbcfb28a6dcd65b0f1da3646edf5c4a"}) });
Related tools
Skill: Convert anything to markdown
POST /api/skill/any-to-markdownConvert anything at a URL - HTML, PDF, or an image - to clean markdown. The 'I have a URL but it might be any content-ty…
Skill: API health check
POST /api/skill/api-healthIs this API endpoint healthy? Liveness check, response headers, and TLS certificate status in one pass. API health check…
Skill: API investigation
POST /api/skill/api-investigationPoint at an unknown API endpoint and figure out how to use it: auth scheme, content type, version, rate limits, OpenAPI/…
Skill: Article digest
POST /api/skill/article-digestQuick research brief on any topic - web search results plus an AI-generated answer in one pass. Article digest skill pac…
Skill: Brand protection
POST /api/skill/brand-protectionIs this domain legitimate? WHOIS age, DNS resolution, scam/phishing search results, and HTTP headers for a quick trust a…
Skill: Cheapest rail right now
POST /api/skill/cheapest-railWhere should an agent transact this minute? Live gas on Ethereum + every major L2 side by side, Base gas tiers, a fee es…