{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "convoy",
    "name": "Convoy",
    "vendor": "Frain Technologies Inc.",
    "vendorUrl": "https://www.getconvoy.io",
    "kind": "http-api",
    "category": "webhooks",
    "summary": "Convoy is a webhooks gateway from Frain Technologies. It sends outgoing webhooks with retries and signatures and receives incoming ones, through an HTTP API on Convoy Cloud or a self-hosted, source-available server.",
    "url": "https://www.anchorterminal.com/tools/convoy",
    "markdownUrl": "https://www.anchorterminal.com/tools/convoy.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/convoy.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/convoy.json",
    "repo": "https://github.com/frain-dev/convoy",
    "license": "Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "npm",
        "name": "convoy.js"
      },
      {
        "registry": "pypi",
        "name": "convoy-python"
      },
      {
        "registry": "go",
        "name": "github.com/frain-dev/convoy-go/v2"
      }
    ],
    "auth": "api-key",
    "authNotes": "Self-serve API keys sent as a Bearer token. A project API key is scoped to one project and is returned once when the project is created, or regenerated in project settings. A personal API key, created in the dashboard's security settings, follows its user's organisation membership and creates projects. No OAuth for API clients and no partner or sales approval. On self-hosted instances `convoy bootstrap --with-api-key` prints a personal key.",
    "pricing": "paid",
    "pricingNotes": "Convoy Cloud has a 14-day trial without a card (one project, one user, 100 events a day), then Pro at $99 a month for 25 events a second or Premium at $499 a month. Plans are flat with a throughput limit and no per-message charge. The self-hosted Community edition is free with one user and two projects, and self-hosted Premium is $999 a month (https://www.getconvoy.io/pricing, checked 2026-10-08).",
    "priceSummary": "$99 / mo",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI spec or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 2877,
      "npmWeekly": 2257,
      "pypiWeekly": 679,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.getconvoy.io/docs",
    "llmsTxt": "https://www.getconvoy.io/docs/llms.txt",
    "openapi": "https://raw.githubusercontent.com/frain-dev/convoy/main/docs/v3/openapi3.json",
    "capabilities": [
      "events.webhooks-send",
      "events.webhooks-receive"
    ],
    "tags": [
      "hosted",
      "self-hosted",
      "source-available",
      "webhooks",
      "api-key",
      "openapi",
      "llms-txt",
      "no-card",
      "status-page",
      "go",
      "python",
      "typescript",
      "ruby"
    ],
    "lastRelease": "2026-09-27",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 62.2,
      "grade": "B",
      "agentReady": false,
      "rank": 308,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 69,
        "maintenance": 80,
        "payments": 30,
        "reliability": 92,
        "schema": 78,
        "security": 53,
        "transparency": 67
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 92,
          "points": 18.4,
          "reason": "Graded as a hosted service, Convoy Cloud. status.getconvoy.io on incident.io lists the website and the US and EU data and control planes, with data since July 2024 (20). It shows 100 per cent uptime on every component from July to October 2026 and no incidents, though the day-by-day calendar didn't load for us (30). Cloud Pro is limited to 25 events a second, and the docs give defaults of 1,000 API requests and 1,000 ingested events a second for self-hosted instances (15). The docs say a breach returns 429 and document idempotency keys on events, but give no Retry-After or backoff guidance for API clients, although the server code sets Retry-After (10). The pricing page lists a 99.99 per cent uptime SLA on Pro and 99.999 on Premium. No SLA document was found (7). The API is generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "OpenAPI 3.0 spec in the public repository, 68 operations on 49 paths with 153 schemas, and the API reference is generated from it (25). llms.txt, with every documentation page also served as Markdown (10). Every operation has a description, but most are one line such as \"This endpoint retries an event delivery\" and none says when not to use it (10). 32 enums and typed request models, though `models.CreateEvent` marks no field as required (10). 58 examples. Every operation lists 400, 401 and 404, while the errors page documents four codes and one sample body, and 429 isn't in the spec (8). Dated API versions with `X-Convoy-Version`, a compatibility matrix and a per-release CHANGELOG.md. The spec's own version field reads 26.3.5 against release 26.8.0 (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 69,
          "points": 11.21,
          "reason": "List sizes are set with `perPage` (default 50), with no field selection or summaries, and event bodies come back whole (12). Cursor pagination in both directions, with filters by date range, endpoint, source and idempotency key (20). Errors are `{\"status\": false, \"message\": ...}` with conventional HTTP codes. Messages are specific, but only four codes are documented and there are no machine-readable error codes (10). `idempotency_key` on event creation plus replay and retry endpoints. Endpoint and subscription creates have no idempotency key, and the onboarding guide says to look up by `ownerId` first (15). An event needs only an endpoint id, an event type and data. SDKs for JavaScript, Python, Go and Ruby, with convoy.js last published on 13 November 2023 (12)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 53,
          "points": 9.28,
          "reason": "Bearer API keys. A project key is limited to one project, a personal key to its user's organisations, and both can be regenerated or revoked. No OAuth for API clients, and we found no per-action scopes on a key (22). Roles include a read-only project viewer, listed as paid for self-hosted instances and on Cloud Premium. Whether an API key can be issued read-only wasn't established, and deletes need no confirmation (8). Incoming webhook payloads are third-party content. The docs cover signature verification and SSRF but give no guidance for agents reading payloads (5). Every delivery attempt is logged with request and response. No audit log of API or dashboard actions was found (7). No security.txt and no SECURITY.md. GitHub private vulnerability reporting is on, one advisory was published in July 2026, and the repository runs CodeQL, OSV and Trivy workflows. The pricing page lists SOC 2, and the trust centre couldn't be read (11)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "Graded on Convoy Cloud. No x402, MPP or L402 (0). Flat plan prices are public, Pro at $99 and Premium at $499 a month, with no per-message price (10). A 14-day trial without a card, limited to 100 events a day (20). A person has to sign up in a browser to get a Cloud key (0). The self-hosted Community edition is free and `convoy bootstrap --with-api-key` prints a key without a signup, which this score doesn't count because the hosted service is what we graded."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 80,
          "points": 7,
          "reason": "v26.8.0 was tagged on 27 September 2026, 11 days before this check (30). 22 version tags between 27 June and 27 September 2026 (20). The issues page shows 34 open issues, the most recently updated on 14 September 2026 and many untouched since 2023. Support runs through a community Slack and GitHub (12). convoy-python 0.2.0 was published on 21 July 2026 and a workflow regenerates SDKs from the spec, but convoy.js on npm dates from 13 November 2023 (10). The repository has integration, end-to-end, lint, CodeQL and nightly OSV workflows. We couldn't read their current pass state (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 67,
          "points": 5.86,
          "note": "editorial 65, provenance 69",
          "reason": "The gateway's source is public under the Elastic Licence 2.0, which isn't an OSI licence and bars offering it as a hosted service. The OpenAPI spec still names the MPL 2.0 (20). A privacy notice dated 1 June 2023 that still cites Privacy Shield, a DPA with deletion within 60 days of termination and breach notice without undue delay, and a Cloud subscription policy with dated suspension and deletion steps. The terms name no legal entity (15). The Cloud upgrade policy promises at least 180 days' notice of major upgrades and deprecations, and breaking API changes are listed by version (20). US and EU regions are named and self-hosted telemetry is documented with an opt-out (`CONVOY_ANALYTICS_ENABLED=false`). The sub-processor list at trust.getconvoy.io didn't render for us (10)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "List sizes are set with `perPage` (default 50), with no field selection or summaries, and event bodies come back whole (12). Cursor pagination in both directions, with filters by date range, endpoint, source and idempotency key (20). Errors are `{\"status\": false, \"message\": ...}` with conventional HTTP codes. Messages are specific, but only four codes are documented and there are no machine-readable error codes (10). `idempotency_key` on event creation plus replay and retry endpoints. Endpoint and subscription creates have no idempotency key, and the onboarding guide says to look up by `ownerId` first (15). An event needs only an endpoint id, an event type and data. SDKs for JavaScript, Python, Go and Ruby, with convoy.js last published on 13 November 2023 (12).",
          "maintenance": "v26.8.0 was tagged on 27 September 2026, 11 days before this check (30). 22 version tags between 27 June and 27 September 2026 (20). The issues page shows 34 open issues, the most recently updated on 14 September 2026 and many untouched since 2023. Support runs through a community Slack and GitHub (12). convoy-python 0.2.0 was published on 21 July 2026 and a workflow regenerates SDKs from the spec, but convoy.js on npm dates from 13 November 2023 (10). The repository has integration, end-to-end, lint, CodeQL and nightly OSV workflows. We couldn't read their current pass state (8).",
          "payments": "Graded on Convoy Cloud. No x402, MPP or L402 (0). Flat plan prices are public, Pro at $99 and Premium at $499 a month, with no per-message price (10). A 14-day trial without a card, limited to 100 events a day (20). A person has to sign up in a browser to get a Cloud key (0). The self-hosted Community edition is free and `convoy bootstrap --with-api-key` prints a key without a signup, which this score doesn't count because the hosted service is what we graded.",
          "reliability": "Graded as a hosted service, Convoy Cloud. status.getconvoy.io on incident.io lists the website and the US and EU data and control planes, with data since July 2024 (20). It shows 100 per cent uptime on every component from July to October 2026 and no incidents, though the day-by-day calendar didn't load for us (30). Cloud Pro is limited to 25 events a second, and the docs give defaults of 1,000 API requests and 1,000 ingested events a second for self-hosted instances (15). The docs say a breach returns 429 and document idempotency keys on events, but give no Retry-After or backoff guidance for API clients, although the server code sets Retry-After (10). The pricing page lists a 99.99 per cent uptime SLA on Pro and 99.999 on Premium. No SLA document was found (7). The API is generally available (10).",
          "schema": "OpenAPI 3.0 spec in the public repository, 68 operations on 49 paths with 153 schemas, and the API reference is generated from it (25). llms.txt, with every documentation page also served as Markdown (10). Every operation has a description, but most are one line such as \"This endpoint retries an event delivery\" and none says when not to use it (10). 32 enums and typed request models, though `models.CreateEvent` marks no field as required (10). 58 examples. Every operation lists 400, 401 and 404, while the errors page documents four codes and one sample body, and 429 isn't in the spec (8). Dated API versions with `X-Convoy-Version`, a compatibility matrix and a per-release CHANGELOG.md. The spec's own version field reads 26.3.5 against release 26.8.0 (15).",
          "security": "Bearer API keys. A project key is limited to one project, a personal key to its user's organisations, and both can be regenerated or revoked. No OAuth for API clients, and we found no per-action scopes on a key (22). Roles include a read-only project viewer, listed as paid for self-hosted instances and on Cloud Premium. Whether an API key can be issued read-only wasn't established, and deletes need no confirmation (8). Incoming webhook payloads are third-party content. The docs cover signature verification and SSRF but give no guidance for agents reading payloads (5). Every delivery attempt is logged with request and response. No audit log of API or dashboard actions was found (7). No security.txt and no SECURITY.md. GitHub private vulnerability reporting is on, one advisory was published in July 2026, and the repository runs CodeQL, OSV and Trivy workflows. The pricing page lists SOC 2, and the trust centre couldn't be read (11).",
          "transparency": "The gateway's source is public under the Elastic Licence 2.0, which isn't an OSI licence and bars offering it as a hosted service. The OpenAPI spec still names the MPL 2.0 (20). A privacy notice dated 1 June 2023 that still cites Privacy Shield, a DPA with deletion within 60 days of termination and breach notice without undue delay, and a Cloud subscription policy with dated suspension and deletion steps. The terms name no legal entity (15). The Cloud upgrade policy promises at least 180 days' notice of major upgrades and deprecations, and breaking API changes are listed by version (20). US and EU regions are named and self-hosted telemetry is documented with an opt-out (`CONVOY_ANALYTICS_ENABLED=false`). The sub-processor list at trust.getconvoy.io didn't render for us (10)."
        },
        "sources": [
          {
            "what": "pricing and plan limits",
            "url": "https://www.getconvoy.io/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "docs index (llms.txt)",
            "url": "https://www.getconvoy.io/docs/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "API authentication",
            "url": "https://www.getconvoy.io/docs/api-reference/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "API versioning and breaking changes",
            "url": "https://www.getconvoy.io/docs/api-reference/versioning",
            "seen": "2026-10-08"
          },
          {
            "what": "API errors",
            "url": "https://www.getconvoy.io/docs/api-reference/errors",
            "seen": "2026-10-08"
          },
          {
            "what": "pagination",
            "url": "https://www.getconvoy.io/docs/api-reference/pagination",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits",
            "url": "https://www.getconvoy.io/docs/product-manual/rate-limits",
            "seen": "2026-10-08"
          },
          {
            "what": "idempotency",
            "url": "https://www.getconvoy.io/docs/product-manual/idempotency",
            "seen": "2026-10-08"
          },
          {
            "what": "signatures",
            "url": "https://www.getconvoy.io/docs/product-manual/signatures",
            "seen": "2026-10-08"
          },
          {
            "what": "retry schedule",
            "url": "https://www.getconvoy.io/docs/glossary/retry-schedule",
            "seen": "2026-10-08"
          },
          {
            "what": "API-driven onboarding",
            "url": "https://www.getconvoy.io/docs/guides/api-onboarding",
            "seen": "2026-10-08"
          },
          {
            "what": "RBAC",
            "url": "https://www.getconvoy.io/docs/product-manual/rbac",
            "seen": "2026-10-08"
          },
          {
            "what": "paid plan list and Community limits",
            "url": "https://www.getconvoy.io/docs/business-and-enterprise/paid-features",
            "seen": "2026-10-08"
          },
          {
            "what": "SDKs and Cloud base URLs",
            "url": "https://www.getconvoy.io/docs/sdk/sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "telemetry",
            "url": "https://www.getconvoy.io/docs/resources/telemetry",
            "seen": "2026-10-08"
          },
          {
            "what": "Cloud upgrade policy",
            "url": "https://www.getconvoy.io/docs/cloud/cloud-upgrade-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "Cloud subscription policy",
            "url": "https://www.getconvoy.io/docs/cloud/cloud-subscription-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.getconvoy.io",
            "seen": "2026-10-08"
          },
          {
            "what": "repository (LICENSE, CHANGELOG.md, tags, workflows, OpenAPI spec), cloned",
            "url": "https://github.com/frain-dev/convoy",
            "seen": "2026-10-08"
          },
          {
            "what": "security advisory",
            "url": "https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4",
            "seen": "2026-10-08"
          },
          {
            "what": "security policy tab (none set)",
            "url": "https://github.com/frain-dev/convoy/security/policy",
            "seen": "2026-10-08"
          },
          {
            "what": "open issues",
            "url": "https://github.com/frain-dev/convoy/issues",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of use",
            "url": "https://www.getconvoy.io/legal/Terms-of-Use-Convoy.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy notice",
            "url": "https://www.getconvoy.io/legal/privacy-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "DPA",
            "url": "https://www.getconvoy.io/legal/dpa",
            "seen": "2026-10-08"
          },
          {
            "what": "npm convoy.js",
            "url": "https://registry.npmjs.org/convoy.js",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI convoy-python",
            "url": "https://pypi.org/pypi/convoy-python/json",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for getconvoy.io",
            "url": "https://rdap.identitydigital.services/rdap/domain/getconvoy.io",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the trust centre at trust.getconvoy.io and its sub-processor list render only with JavaScript, so SOC 2 status and sub-processors rest on the pricing page's claim and the DPA's link",
          "unchecked: the day-by-day incident calendar on status.getconvoy.io didn't load. The 90-day record rests on the page's 100 per cent uptime figures and its empty incident feed",
          "unchecked: the GitHub API refused us for its rate limit. Stars (2,877) come from the repository page, and the pass state of CI on main wasn't read",
          "Whether an API key can be issued with a read-only role on Convoy Cloud wasn't established from the docs",
          "No SLA document was found behind the uptime percentages on the pricing page",
          "The Cloud signup page wasn't exercised, so the no-card trial rests on the pricing page",
          "First release date not established from a 200-commit clone"
        ]
      },
      "negative": -6,
      "negativeNotes": [
        "2026-07-24. Advisory GHSA-p5vg-v7mj-f6q4, rated High. Before v26.6.8 any caller authorised on one project could read another project's source record by id, including message broker credentials in plaintext. Patched in 26.6.8 and published by the maintainers, so the deduction is reduced to 4 (https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4).",
        "2026-08-04. Until v26.7.0 the events list returned `metadata` on dynamic events, which carried the endpoint secret and custom auth headers in plaintext. The field was removed across every API version and the change is documented, so the deduction is 2 (https://www.getconvoy.io/docs/api-reference/versioning)."
      ],
      "verdict": "Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.",
      "bestFor": "A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.",
      "strengths": [
        "Public OpenAPI 3.0 spec with 68 operations, plus llms.txt and Markdown copies of every documentation page",
        "Event creation accepts an `idempotency_key`, and the API has single and batch replay and retry endpoints for events and deliveries",
        "Dated API versions (current default 2025-11-24) pinned per request with the `X-Convoy-Version` header",
        "22 tagged releases between 27 June and 27 September 2026, with breaking changes listed per release in CHANGELOG.md",
        "Convoy Cloud's upgrade policy promises at least 180 days' notice of major upgrades and deprecations"
      ],
      "weaknesses": [
        "Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8",
        "Until v26.7.0 (4 August 2026) the events list returned endpoint secrets and custom auth headers in plaintext for dynamic events",
        "No security.txt and no SECURITY.md. The trust centre at trust.getconvoy.io renders only with JavaScript, so we couldn't read it",
        "The errors page documents four HTTP codes and one sample body. 429 and Retry-After aren't in the API reference",
        "Cloud needs a browser signup, and the 14-day trial allows 100 events a day, one project and one user"
      ],
      "agentNotes": [
        "Use the regional base URL, https://us.getconvoy.cloud/api/v1 or https://eu.getconvoy.cloud/api/v1. A project key works only under /projects/{projectID}/",
        "Create an endpoint, then a subscription, then the event. An event sent to an endpoint with no subscription isn't dispatched",
        "Send `idempotency_key` on every event. A repeated key creates the event but no delivery, and the key stays reserved until retention deletes the event",
        "Create projects with a personal API key and the `orgID` query parameter. The project key in that response is shown once",
        "Before retrying an endpoint or subscription create, list endpoints by `ownerId`. Idempotency keys cover event ingestion only"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 62.2
        }
      ],
      "editorialScores": {
        "ergonomics": 69,
        "maintenance": 80,
        "payments": 30,
        "reliability": 92,
        "schema": 78,
        "security": 53,
        "transparency": 65
      },
      "provenanceScore": 69
    },
    "connect": {
      "install": "curl -fsSL https://getconvoy.io/install | bash",
      "http": "curl --request POST \\\n  --url https://{region}.getconvoy.cloud/api/v1/projects/\u003cproject-id\u003e/events \\\n  --header 'Authorization: Bearer \u003capi-key\u003e' \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"endpoint_id\": \"\u003cendpoint-id\u003e\", \"event_type\": \"payment.success\", \"data\": {\"status\": \"Completed\"}}'"
    },
    "letme": {
      "capability": "https://letme.dev/events.webhooks-send",
      "tool": "https://letme.dev/convoy"
    },
    "notable": [
      "The API reference is generated from an OpenAPI 3.0 spec in the repository with 68 operations across endpoints, events, subscriptions, filters, sources, portal links and deliveries (https://github.com/frain-dev/convoy/blob/main/docs/v3/openapi3.json)",
      "Advisory GHSA-p5vg-v7mj-f6q4, published 24 July 2026 and rated High, describes a cross-project read of source records with plaintext broker credentials, patched in 26.6.8 (https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4)",
      "v26.7.0 removed `metadata` from the events list because it carried the endpoint secret and custom auth headers in plaintext on dynamic events (https://www.getconvoy.io/docs/api-reference/versioning)",
      "Cloud plans are flat. Pro is $99 a month for 25 events a second with 7-day retention, Premium $499 a month, and both list an uptime SLA (https://www.getconvoy.io/pricing)",
      "The repository's LICENSE file is the Elastic Licence 2.0, which bars offering the software as a hosted service, while the OpenAPI spec's info block still names the MPL 2.0 (https://github.com/frain-dev/convoy/blob/main/LICENSE)",
      "The Community edition is limited to one user, one organisation and two projects (https://www.getconvoy.io/docs/business-and-enterprise/paid-features)",
      "status.getconvoy.io shows 100 per cent uptime from July to October 2026 on the website and on the US and EU data and control planes, with no open incidents (https://status.getconvoy.io)"
    ],
    "area": "developer",
    "details": [
      {
        "label": "Surface graded",
        "value": "Convoy Cloud's HTTP API at https://us.getconvoy.cloud/api and https://eu.getconvoy.cloud/api. The self-hosted gateway serves the same API from the same spec. No MCP server found"
      },
      {
        "label": "API",
        "value": "OpenAPI 3.0, 68 operations on 49 paths. Projects, endpoints, events, event deliveries, delivery attempts, subscriptions, filters, sources, event types, portal links, meta events, bulk onboard"
      },
      {
        "label": "Credentials",
        "value": "Bearer token. A project API key is scoped to one project. A personal API key follows its user's organisation membership and creates and lists projects with `orgID`"
      },
      {
        "label": "Sending",
        "value": "Direct, fan-out by `owner_id`, broadcast by event type, and dynamic events that carry their own endpoint URL. Events also arrive from Kafka, Amazon SQS, Google Pub/Sub and RabbitMQ"
      },
      {
        "label": "Receiving",
        "value": "Incoming projects take third-party webhooks at a source URL, verify them and route them to endpoints through subscriptions with filters"
      },
      {
        "label": "Retries",
        "value": "Linear or exponential backoff, set per project. Default backoff schedule 10 s, 30 s, 1 min, 3 min, 5 min, 10 min, 15 min. Manual, force and batch retry, single and batch replay"
      },
      {
        "label": "Signatures",
        "value": "HMAC in `X-Convoy-Signature`, hex or base64. Advanced signatures add a timestamp and several `v1` hashes so secrets can roll. An endpoint for rolling a secret is in the API"
      },
      {
        "label": "Idempotency",
        "value": "`idempotency_key` on event creation, forwarded to the receiver as `X-Convoy-Idempotency-Key`. Incoming sources can take the key from a header, body field or query parameter"
      },
      {
        "label": "Rate limits",
        "value": "Cloud Pro 25 events a second, custom on Premium. Self-hosted defaults 1,000 API requests a second and 1,000 ingested events a second, both configurable. Over the limit returns 429"
      },
      {
        "label": "Pagination",
        "value": "Cursor based with `perPage` (default 50), `next_page_cursor`, `prev_page_cursor` and `direction`. Event lists filter by date range, endpoint, source and idempotency key"
      },
      {
        "label": "Versioning",
        "value": "Dated API versions 2024-01-01, 2024-04-01 and 2025-11-24, pinned per request with `X-Convoy-Version`. Security fixes can remove a response field across every version"
      },
      {
        "label": "SDKs",
        "value": "convoy.js (npm 1.1.0, published 13 November 2023), convoy-python (PyPI 0.2.0, 21 July 2026), convoy-go v2 and convoy.rb in the docs. A repository workflow also names PHP and Java SDK repositories"
      },
      {
        "label": "Self-hosted",
        "value": "Community edition free with one user, one organisation and two projects. Needs PostgreSQL and Redis. `convoy bootstrap --with-api-key` prints a personal API key without the dashboard"
      },
      {
        "label": "Licence",
        "value": "Elastic Licence 2.0. Source available, no offering it as a hosted service and no bypassing the licence key. SDKs are MIT per npm"
      },
      {
        "label": "Status",
        "value": "status.getconvoy.io on incident.io. Website, data plane and control plane for the US and EU regions, with data since July 2024"
      },
      {
        "label": "Cloud changes",
        "value": "Minor upgrades every two weeks. Major upgrades and deprecations come with at least 180 days' notice by Slack and email, per the Cloud upgrade policy"
      }
    ],
    "unitPrices": [
      {
        "item": "Cloud Pro",
        "unit": "month",
        "usd": 99,
        "note": "25 events a second, 7-day retention"
      },
      {
        "item": "Cloud Premium",
        "unit": "month",
        "usd": 499,
        "note": "custom rate limits and retention"
      },
      {
        "item": "Self-hosted Premium licence",
        "unit": "month",
        "usd": 999,
        "note": "Community edition is free"
      }
    ],
    "provenance": {
      "legalEntity": "Frain Technologies Inc.",
      "domain": "getconvoy.io",
      "domainRegistered": "2021-09-06",
      "endpointOnVendorDomain": false,
      "terms": "https://www.getconvoy.io/legal/Terms-of-Use-Convoy.pdf",
      "privacy": "https://www.getconvoy.io/legal/privacy-policy",
      "statusPage": "https://status.getconvoy.io",
      "changelog": "https://github.com/frain-dev/convoy/blob/main/CHANGELOG.md",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The repository's LICENSE file names Frain Technologies Inc. as licensor, and the home page footer names Frain Technologies at 2261 Market Street, San Francisco, CA 94114. The terms and privacy notice say only Convoy and its affiliates, with info@frain.dev as contact.",
        "The Cloud API answers at us.getconvoy.cloud and eu.getconvoy.cloud, a different registered domain from getconvoy.io. The vendor's own docs and OpenAPI spec name both hosts.",
        "www.getconvoy.io/.well-known/security.txt returns 404. us.getconvoy.cloud returns the dashboard's HTML at that path. The GitHub repository has no SECURITY.md but accepts private vulnerability reports.",
        "The privacy notice is dated 1 June 2023. The DPA at getconvoy.io/legal/dpa points to a sub-processor list at trust.getconvoy.io/subprocessors, which renders only with JavaScript and which we couldn't read.",
        "RDAP for getconvoy.io gives a registration date of 2021-09-06."
      ],
      "score": 69,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Frain Technologies Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "getconvoy.io, registered 2021-09-06 (5 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": " is not on getconvoy.io",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 5 of the 8 things a reader expects",
          "points": 7.8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.getconvoy.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.getconvoy.io/legal/Terms-of-Use-Convoy.pdf",
          "state": "not-read",
          "points": 10,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://www.getconvoy.io/legal/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2023-06-01",
          "words": 1855,
          "points": 7.8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: June 1, 2023",
              "says": "Last updated 2023-06-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": false
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "(\"CCPA\"), as applicable (collectively, the \"Applicable Data Protection Laws\"), the Company is acting as a processor/service provider, and the User is acting as the controller/business, as applicable."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "(ii) not sell Personal Data (as defined under the CCPA);",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "For the purposes of (i) the General Data Protection Regulation (2016/679) (\"GDPR\"), including any subordinate or implementing legislation, (ii) the EU-US Privacy Shield (\"Privacy Shield\"), and (iii) the California Consumer Privacy Act of 2018, Cal."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "The User can exercise the User's rights of access, rectification, erasure, restriction, objection, and data portability by contacting the Company at [email protected].",
              "says": "Gives an email address, hidden from our reader by the page"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Last updated: June 1, 2023"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The notice states that it does not cover content the user processes or stores through the services.",
              "quote": "This PN does not apply to any content processed and/or stored by the User when using the Services."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/convoy.json",
    "live": {
      "slug": "convoy",
      "vendorStatus": {
        "page": "https://status.getconvoy.io",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T18:21:55.078010278Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "frain-dev/convoy",
          "version": "v26.8.0",
          "released": "2026-09-28",
          "seenAt": "2026-10-08T16:07:07.309156702Z"
        },
        {
          "registry": "npm",
          "name": "convoy.js",
          "version": "1.1.0",
          "seenAt": "2026-10-08T16:07:02.917445318Z"
        },
        {
          "registry": "pypi",
          "name": "convoy-python",
          "version": "0.2.0",
          "released": "2023-05-16",
          "seenAt": "2026-10-08T16:07:07.117567905Z"
        }
      ],
      "githubStars": 2877,
      "npmWeekly": 2257,
      "pypiWeekly": 679,
      "securityTxt": {
        "url": "https://getconvoy.io/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:39:08.354465852Z"
      },
      "pages": [
        {
          "url": "https://raw.githubusercontent.com/frain-dev/convoy/main/CHANGELOG.md",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:24:09.887860175Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "91084795c305"
        }
      ],
      "updatedAt": "2026-10-08T18:24:09.887860175Z"
    }
  }
}
