Best of · Developer & infrastructure

Best webhook and event delivery infrastructure for AI agents

The 10 highest-scoring of 11 webhook and event delivery infrastructure on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.

  • 11 ranked
  • 5 agent-ready
  • 8 hosted endpoints
  • Updated 9 October 2026

Top three

Picks by need

Worked out from the scores, prices and facts, so they change when the research does.

Highest score overall

Hookdeck BB

BB, 76.9/100 on the benchmark.

Also Ably, BB, 75/100.

Reliability

Convoy B

92/100 on reliability, against 90 for the overall leader.

Agent ergonomics

Ably BB

87/100 on agent ergonomics, against 81 for the overall leader.

Security & auth

Amazon EventBridge BB

88/100 on security & auth, against 67 for the overall leader.

Maintenance & community

Svix BB

88/100 on maintenance & community, against 74 for the overall leader.

Transparency & trust

Amazon EventBridge BB

87/100 on transparency & trust, against 76 for the overall leader.

A hosted MCP endpoint

Upstash QStash BB

remote MCP server, nothing to install.

Self-hosting under an open licence

Svix BB

self-hosted, MIT for the server licence.

Also Hook0, self-hosted, SSPL-1 licence.

The shortlist

#ToolGradeBest forPriceWhere
1 Hookdeck
Hookdeck Technologies Inc.
BB 76.9 Teams that receive third-party webhooks and want queueing, retries, replay and an agent that can inspect failures or pause a connection. $39 / mo hosted and local
2 Ably
Ably Realtime Ltd
BB 75 Fan-out of live messages to many connected clients, presence and resumable streams, with webhooks and queues as ways to get channel events to a backend. $29 / mo hosted
3 Svix
Svix Inc.
BB 74 A product that must send webhooks to its own customers with signing, retries, replay and a consumer portal, and an agent that builds or operates that integration. $20 / mo hosted
4 Amazon EventBridge
Amazon Web Services
BB 73.7 Teams already on AWS that want events routed between AWS services, their own code and outside HTTPS endpoints under IAM, with retention and replay on the bus. $0.18 / GB hosted
5 Upstash QStash
Upstash
BB 72.3 Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue. $0.05 / GB hosted
6 PubNub
PubNub Inc.
B 68.1 Live fan-out to many connected clients with presence and history, and for an agent that manages a PubNub account through MCP. $98 / mo hosted and local
7 Hook0
FGRibreau SARL
B 64.6 A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code. Freemium local
8 Centrifugo
Centrifugal Labs LTD
B 63.1 A team that wants to run its own realtime channel server and publish to browsers and apps from any backend, with history, recovery and presence. Free · OSS local
9 Convoy
Frain Technologies Inc.
B 62.2 A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward. $99 / mo local
10 Webhook Relay
AppScension Ltd
C 57.8 Teams that need third-party webhooks to reach localhost, on-premises CI or private Kubernetes services, with an agent that can configure buckets and inspect failed deliveries over MCP. $8.99 / mo hosted

1 more are ranked in the full table.

How to choose

  1. Retry schedule and limitsCheck the retry schedule, attempt limit and when an event is marked failed, since a short limit can drop events a flaky endpoint would accept later.
  2. Duplicates and event orderCheck whether delivery is at least once or at most once, and whether order holds, so the agent knows if it must handle repeats itself.
  3. Signature checks and replayCheck how signatures are verified and whether a failed event can be replayed from the delivery log, so an agent can trust what it receives.
  4. Billing for retriesCheck whether retries and failed attempts are billed, since a flaky endpoint can multiply the sends an agent pays for.

How the benchmark tests this category. The same thousand events sent through each listing to an endpoint that fails one request in ten. We check retries and their schedule, ordering, duplicate delivery, signature verification, replay of a failed event and the delivery log. In this run listings are graded from public evidence against the published checklist.

Each one in detail

#1

Hookdeck

BB 76.9/100

Hookdeck Event Gateway is a hosted service that receives webhooks, queues them and sends them on to HTTP destinations with filters, transformations, retries and replay. Agents use its REST API or the stdio MCP server in the Hookdeck CLI.

Verdict API keys carry per-resource read or write scopes and can be rolled by API, and the MCP server starts read-only with annotations on every tool. The official Go SDK was last updated in December 2024 and the TypeScript SDK is deprecated. No audit log or prompt-injection guidance was found in the reviewed documentation.

Choose it for Teams that receive third-party webhooks and want queueing, retries, replay and an agent that can inspect failures or pause a connection.

Strengths

  • API keys take read or write scopes per resource family, project and resource grants, and rollover with a 0, 1 or 24 hour overlap
  • The MCP server registers 17 tools in read-only mode and 25 with --allow-write, each with readOnlyHint and destructiveHint set in the source
  • Public OpenAPI 3.0.1 spec with 135 operations, llms.txt and a Markdown version of every docs page

Weaknesses

  • Go SDK last committed 11 December 2024 and the TypeScript SDK is marked deprecated, so current clients are the CLI, Terraform and raw HTTP
  • The MCP server is labelled beta, runs over stdio only and is not listed in the official MCP registry
  • No idempotency key on REST writes. Safe retries depend on upsert by name with PUT

Price $39 / moAuth API keyx402 nohosted and local

Full assessment

#2

Ably

BB 75/100

Hosted realtime messaging from Ably Realtime Ltd in London. Clients publish and subscribe on channels over WebSocket, SSE or MQTT, with a REST API, presence, message history, outbound and inbound webhooks, and AMQP queues.

Verdict Pub/sub channels with per-channel capabilities on keys and tokens, idempotent publishing by message id, published limits for every plan and a 99.999 per cent SLA on paid plans. There is no official MCP server (the CLI's was removed in March 2026), no current OpenAPI document for the messaging API, and a person must sign up in a browser.

Choose it for Fan-out of live messages to many connected clients, presence and resumable streams, with webhooks and queues as ways to get channel events to a backend.

Strengths

  • API keys and tokens carry per-channel capabilities (publish, subscribe, history and 16 others), and tokens can be revoked by client, channel or revocation key
  • A message id or X-Ably-MessageId header makes a REST publish idempotent, and current SDKs set one by default
  • Limits are published per plan, including 50 HTTP requests a second on Free and 50 publishes a second per channel on every plan

Weaknesses

  • No official MCP server. The Ably CLI's built-in one was removed in v0.17.0 on 8 March 2026
  • The served OpenAPI document covers only the Control API (24 operations). The messaging REST API's spec sits in a repository marked deprecated in August 2024
  • Inbound webhooks and SSE put the API key or token in the URL query string

Price $29 / moAuth API keyx402 nohosted

Full assessment · Against #1, Hookdeck

#3

Svix

BB 74/100

Svix is a webhook sending service with a hosted REST API and an MIT-licensed server. One call creates a message, and Svix signs it, sends it to each subscribed endpoint, retries failures and logs every attempt.

Verdict The hosted REST API has a public OpenAPI 3.1 spec with 141 operations, Idempotency-Key on 44 POST operations, and a published retry schedule of eight attempts. An API key can make any call for its environment, with no read-only or scoped key, and a person must create that key in the dashboard.

Choose it for A product that must send webhooks to its own customers with signing, retries, replay and a consumer portal, and an agent that builds or operates that integration.

Strengths

  • OpenAPI 3.1 spec with 141 operations, each described, and code samples on 140 of them
  • Idempotency-Key accepted on 44 POST operations, with the first result replayed for up to 12 hours
  • Published retry schedule of eight attempts over about 27.5 hours, with resend and recover calls for failed messages

Weaknesses

  • An API key can make any API call for its environment. No read-only or scoped API key was found in the reviewed documentation
  • A person must create the first API key in the dashboard. No programmatic signup or key API was found
  • 429 is in the spec for every operation, but no Retry-After header or backoff guidance was found, and the JavaScript SDK retries only on 5xx

Price $20 / moAuth API keyx402 nohosted

Full assessment · Against #1, Hookdeck

#4

Amazon EventBridge

BB 73.7/100

Amazon EventBridge is AWS's serverless event bus. Applications, AWS services and SaaS partners publish events, and the bus routes them to targets such as Lambda functions, SQS queues and HTTPS endpoints. It includes Pipes, a scheduler and a schema registry.

Verdict IAM policies scope a credential to single actions and buses, and an SLA commits 99.99 per cent monthly uptime per Region. The Custom Event Bus API of 24 September 2026 adds retention, replay, ordering and publish-time deduplication. Classic PutEvents takes no idempotency token and answers 200 for a bus that does not exist. A person must open the AWS account.

Choose it for Teams already on AWS that want events routed between AWS services, their own code and outside HTTPS endpoints under IAM, with retention and replay on the bus.

Strengths

  • Smithy models published for both APIs, 57 Classic operations and 25 for the Custom Event Bus, with llms.txt and a Markdown twin of each guide page
  • 99.99 per cent monthly uptime commitment per Region under the Amazon EventBridge SLA, last updated 2 May 2022
  • The Custom Event Bus keeps every event for 1 to 365 days, replays from a point in time, orders by event group and suppresses duplicates for 300 seconds

Weaknesses

  • Classic PutEvents has no idempotency token or deduplication, and failed entries come back inside a successful response for the caller to resend
  • A Classic PutEvents call that names a bus that does not exist returns 200 and the event is dropped, per the user guide
  • API destination connections carry Basic, OAuth client credentials or API key authorisation only. No request signature was found, and the target has 5 seconds to answer

Price $0.18 / GBAuth OAuth or keyx402 nohosted

Full assessment · Against #1, Hookdeck

#5

Upstash QStash

BB 72.3/100

Upstash QStash is a hosted HTTP message queue and scheduler. A caller publishes a request to its REST API, and QStash sends it to a public URL with retries, delays, cron schedules, FIFO queues and signed requests.

Verdict A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed.

Choose it for Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.

Strengths

  • Public OpenAPI 3.1 file with 43 operations for messages, queues, schedules, URL groups, the dead letter queue, logs and signing keys
  • Retries default to 3 with exponential backoff capped at one day, and a destination's Retry-After header is honoured
  • Upstash-Deduplication-Id makes a repeated publish safe for 10 minutes, with 202 returned for a duplicate

Weaknesses

  • One full-access token and one read-only token per region. No per-queue or per-destination scopes were found
  • The token is accepted as a qstash_token query parameter, which the webhook receiver guide relies on
  • The Markdown pricing page says retries are free and, in its FAQ, that each retry is billed as a message

Price $0.05 / GBAuth OAuth or keyx402 nohosted

Full assessment · Against #1, Hookdeck

#6

PubNub

B 68.1/100

Hosted realtime messaging from PubNub Inc. in San Francisco. Clients publish and subscribe on channels through SDKs or a REST API, with presence, message history, Functions and event forwarding to webhooks. An Admin API and an MCP server manage accounts.

Verdict Pub/sub channels with a 17-tool MCP server on OAuth, an OpenAPI 3.1 Admin API with scoped, expiring keys, and a Markdown twin of every docs page. Publishes are not deduplicated, so a retry can duplicate a message. Access tokens travel in the URL query string, and the status page records a 20 minute global publish failure on 14 August 2026.

Choose it for Live fan-out to many connected clients with presence and history, and for an agent that manages a PubNub account through MCP.

Strengths

  • Hosted MCP server at https://mcp.pubnub.com with OAuth sign-in and 17 tools, and connections listed and revocable in the Admin Portal
  • The Admin API serves an OpenAPI 3.1 document (125 operations) with dated versions, a two-year version lifecycle and Deprecation and Sunset headers
  • Admin API keys are scoped by resource and by account, app or keyset, expire within one year and are shown once

Weaknesses

  • PubNub does not deduplicate publishes and has no idempotency key, so a retry after an unclear failure creates a second message
  • The REST API carries the Access Manager token as the auth query parameter and the publish key in the URL path
  • Access Manager is off by default. Without it, any holder of the publish and subscribe keys can use every channel on the keyset

Price $98 / moAuth OAuth or keyx402 nohosted and local

Full assessment · Against #1, Hookdeck

#7

Hook0

B 64.6/100

Hook0 is a webhook sending service from FGRibreau SARL in France. An application posts events to a REST API and Hook0 signs, retries and logs deliveries to subscriber endpoints. It runs as an EU-hosted cloud or self-hosted under SSPL-1.0.

Verdict Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise.

Choose it for A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code.

Strengths

  • Public OpenAPI 3.0 document at /api/v1/swagger.json with 56 operations, each with a summary, a description and ten error statuses
  • Service tokens are Biscuit tokens that the holder can narrow offline to one application, an expiry date or a read-only action list
  • Errors follow RFC 7807 with a stable id, and the reference lists 46 codes generated from the API's own /errors endpoint

Weaknesses

  • Six advisories were published between 6 August and 9 September 2026, including a High-rated SSRF in the delivery worker fixed on 11 August
  • The status page records API and delivery downtime on 27 August and 22 September 2026, both traced to the hosting provider
  • The terms give no uptime, latency or support commitment by default. Service levels exist only in a signed Enterprise agreement

Price FreemiumAuth API keyx402 nolocal

Full assessment · Against #1, Hookdeck

#8

Centrifugo

B 63.1/100

Centrifugo is an open-source, self-hosted realtime messaging server from Centrifugal Labs. A backend publishes to channels through its HTTP or gRPC server API, and subscribers receive messages over WebSocket, SSE, HTTP streaming or gRPC.

Verdict Centrifugo is Apache-2.0 software an owner runs, with a 40-operation Swagger file, idempotency keys on publish and seven releases in the 90 days to 28 September 2026. The server API has one all-powerful key, which the docs also accept in the URL, and eleven security advisories were published between February and September 2026, two rated Critical.

Choose it for A team that wants to run its own realtime channel server and publish to browsers and apps from any backend, with history, recovery and presence.

Strengths

  • Apache-2.0 server with binaries for seven platforms, a Docker image, deb and rpm packages, a Helm chart and a Homebrew tap
  • Swagger 2.0 file and api.proto in the repository cover 40 server API operations, and the site serves llms.txt and a full Markdown corpus
  • idempotency_key on publish and broadcast drops duplicates for five minutes per channel on the Memory and Redis engines

Weaknesses

  • Two advisories in 2026 are rated Critical. One is an unauthenticated SSRF fixed in 6.7.0, the other an unauthenticated crash in the protobuf decoder
  • The HTTP server API has one key for every method, set in the config file, with no scopes or read-only key in the open-source edition
  • The docs accept the API key as an api_key URL query parameter, while recommending the X-API-Key header

Price Free · OSSAuth API keyx402 nolocal

Full assessment

#9

Convoy

B 62.2/100

Convoy is a webhooks gateway from Frain Technologies. It sends outgoing webhooks with retries and signatures and receives incoming ones, through an HTTP API on Convoy Cloud or a self-hosted, source-available server.

Verdict Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.

Choose it for A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.

Strengths

  • Public OpenAPI 3.0 spec with 68 operations, plus llms.txt and Markdown copies of every documentation page
  • Event creation accepts an idempotency_key, and the API has single and batch replay and retry endpoints for events and deliveries
  • Dated API versions (current default 2025-11-24) pinned per request with the X-Convoy-Version header

Weaknesses

  • Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8
  • Until v26.7.0 (4 August 2026) the events list returned endpoint secrets and custom auth headers in plaintext for dynamic events
  • No security.txt and no SECURITY.md. The trust centre at trust.getconvoy.io renders only with JavaScript, so we couldn't read it

Price $99 / moAuth API keyx402 nolocal

Full assessment · Against #1, Hookdeck

#10

Webhook Relay

C 57.8/100

Webhook Relay is a hosted service that receives webhooks on a public URL and forwards them to public, private or localhost destinations, with filters, transformations and retries. Agents use its REST API, hosted MCP server or the relay CLI.

Verdict Standalone access tokens carry a role and subscription scopes, and the hosted MCP server documents 40 tools that cover configuration, logs, retries and test sends. No API rate limit, deprecation policy or security.txt was found, the terms date from 2019 and the status page history could not be read.

Choose it for Teams that need third-party webhooks to reach localhost, on-premises CI or private Kubernetes services, with an agent that can configure buckets and inspect failed deliveries over MCP.

Strengths

  • Standalone tokens take a Viewer, Member, Billing or Admin role plus bucket and tunnel subscription scopes, and no token can create or change other tokens
  • Hosted MCP server at https://my.webhookrelay.com/v1/mcp with 40 documented tools, including send_webhook and wait_for_webhook_log for testing the real path
  • Durable retries per output with exponential backoff on schedules of about 25 minutes, 16 hours or 30 days

Weaknesses

  • No request rate limit for the management API was found in the reviewed documentation
  • The terms of service were last updated on 25 November 2019 and the privacy statement on 1 June 2018. No DPA or deprecation policy was found
  • The public changelog stops at server 0.179.20 of 23 May 2026 and CLI 1.34.4 of 8 August 2025

Price $8.99 / moAuth OAuth or keyx402 nohosted

Full assessment · Against #1, Hookdeck

Head to head

All 48 comparisons in this category

Questions

What are the highest-rated webhook and event delivery infrastructure for AI agents?

Hookdeck has the highest benchmark score of the 11 ranked webhook and event delivery infrastructure, 76.9 (BB). Ably is second with 75 (BB).

How many webhook and event delivery infrastructure are agent-ready?

5 of the 11 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.

Which webhook and event delivery infrastructure accept x402 payments?

None of the ranked listings here accepts x402 for its main call yet.

How is this list ranked?

By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.

How this list is made

The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.

Full ranked table · 48 head-to-head comparisons · Best tools in every category

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.