# Webhook Studio MCP server

Keyless webhook endpoints: capture, wait, replay, forward, and generate types from real traffic.

## Links
- Registry page: https://www.getdrio.com/mcp/com-webhook-studio-webhooks
- Website: https://webhook-studio.com/mcp/setup

## Install
- Endpoint: https://webhook-studio.com/mcp
- Auth: Auth required by registry metadata

## Setup notes
- Remote header: Authorization (secret)
- The upstream registry signals required auth or secrets.
- Remote endpoint: https://webhook-studio.com/mcp
- Header: Authorization

## Tools
- create_bucket - Provision a new webhook endpoint (a "bucket") that captures incoming HTTP requests. Returns its id, public ingest url to point a provider at, inbox_url (the live human view to hand back), and signing secret. Pass external_ref — your own stable name like "acme-api:stripe" — so you can re-find this exact bucket later with list_buckets after losing context. Endpoint: https://webhook-studio.com/mcp
- list_buckets - List your webhook endpoints. Pass external_ref to fetch the specific bucket you created earlier under that name — this is how you re-anchor after losing the conversation, since you never need to have stored the bucket id. Endpoint: https://webhook-studio.com/mcp
- get_bucket - Fetch one webhook endpoint by id, including its url and inbox_url. Endpoint: https://webhook-studio.com/mcp
- delete_bucket - Permanently delete a webhook endpoint and its captured events. Endpoint: https://webhook-studio.com/mcp
- latest_event - Get the single most recent event captured by a bucket, optionally filtered by provider and event type. Returns one event with its headers, body and delivery results — the one-shot answer to "what did Stripe last send me". 404 if nothing matches, so you never index into an empty list. Endpoint: https://webhook-studio.com/mcp
- list_events - List events captured by a bucket, newest first, with composable filters: since/until (ISO 8601 or YYYY-MM-DD), provider, type, method, signature_valid, and q (case-insensitive substring over body, content type, method, type and labels). Use cursor for the next page. Endpoint: https://webhook-studio.com/mcp
- get_event - Fetch one captured event by id with its full headers, body, signature verification result (and failure reason), and every outbound delivery attempt. This is how you find out whether your forward actually reached its target and what came back. Endpoint: https://webhook-studio.com/mcp
- wait_for_event - Block until the next matching event arrives on a bucket, or until the timeout. Use this to turn "go click Send test webhook in Stripe" into a synchronous step: call it, tell the human to trigger the event, and it returns as soon as one arrives. Filters (provider, type) mean unrelated traffic does not wake it. Returns the event, or nothing if it times out. Endpoint: https://webhook-studio.com/mcp
- replay_event - Re-send a captured event to any URL — the test runner for a handler you just wrote. preserve_headers defaults to true so the original signature header (e.g. Stripe-Signature) arrives intact. If you changed the body or the receiver verifies with a different secret, pass resign_with (the dev's own signing secret) so the payload is re-signed and their verification code passes unmodified. Returns the response status, latency and body. Endpoint: https://webhook-studio.com/mcp
- forward_bucket - Set up standing forwarding from a bucket to a URL. Pass forward_all:true to forward every event, or condition_tree to forward only matching events (same AND/OR condition grammar the routing engine uses). Creates the destination and routing rule in one call. Endpoint: https://webhook-studio.com/mcp
- list_deliveries - List outbound delivery attempts for a bucket, newest first, with the full request and response of each. Pass success:false to see only failures — the direct answer to "which of my forwards are broken and why". Endpoint: https://webhook-studio.com/mcp
- configure_verification - Turn on HMAC signature verification for a bucket using the provider's own signing secret (e.g. Stripe's whsec_). This is how you finish a "verified webhook" integration end to end. Set secret to the provider secret and hmac_enabled:true in the same call; the signature scheme is auto-detected from the header shape. Endpoint: https://webhook-studio.com/mcp
- list_schemas - List the payload schemas Webhook Studio has learned from this account's real traffic, optionally filtered by provider and event_type. These outlive the payloads they were learned from, so this answers "what shapes do I know about" even after old events are gone. Start here to discover what you can generate types or diffs for. Endpoint: https://webhook-studio.com/mcp
- get_schema - Fetch one learned schema with every field, its type, whether it is optional, and how often it actually appears — the real shape of the payload, derived from what this account received rather than guessed from training data. Endpoint: https://webhook-studio.com/mcp
- diff_schema - Compare two versions of a learned schema and get exactly which fields were added, removed or changed type, each flagged as breaking or not. This is the "why did my handler start failing" answer, produced without reading a single payload. from defaults to the version before to. Endpoint: https://webhook-studio.com/mcp
- generate_types - Generate types, a runtime validator, or a full handler from a learned schema — the payoff of the knowledge layer. Everything is derived from the payloads this account ACTUALLY received, with genuinely-optional fields marked optional, instead of a plausible-but-wrong guess from a model's memory of the provider docs. Pass lang for a bare type (typescript / json-schema / zod), or framework (next / express) for a ready-to-paste handler that validates and hands back a fully-typed event. Endpoint: https://webhook-studio.com/mcp
- find_correlation_keys - List the correlation-key candidates for a learned schema — the fields that look like identifiers (e.g. data.object.id), ranked by how consistently they appear. These are the fields to group events by when reconstructing a lifecycle (a Stripe payment_intent across created -> succeeded, a GitHub PR across its events). Derived from real traffic, so it reflects what THIS account actually receives. Endpoint: https://webhook-studio.com/mcp

## Resources
Not captured

## Prompts
Not captured

## Metadata
- Owner: com.webhook-studio
- Version: 0.1.0
- Runtime: Streamable Http
- Transports: HTTP
- License: Not captured
- Language: Not captured
- Stars: Not captured
- Updated: Jul 24, 2026
- Source: https://registry.modelcontextprotocol.io
