# Best webhook and event delivery infrastructure for AI agents > Hookdeck (BB), Ably (BB) and Svix (BB) lead the 11 ranked webhook and event delivery infrastructure. Picks by need, strengths, weaknesses and prices from the Anchor benchmark. - Canonical: https://www.anchorterminal.com/best/webhooks/ - Markdown: https://www.anchorterminal.com/best/webhooks/index.md (~6,650 tokens) - Slim: https://www.anchorterminal.com/best/webhooks/index.min.md (~1,530 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/best/webhooks/index.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 The 10 highest-scoring of 11 webhook and event delivery infrastructure on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change. - Ranked: 11 · agent-ready (BB or better): 5 · accept x402: 0 · hosted endpoints: 8 - Full ranked table: https://www.anchorterminal.com/categories/webhooks.md - Head-to-head comparisons: https://www.anchorterminal.com/compare/webhooks/index.md (48) - Methodology: https://www.anchorterminal.com/benchmark/index.md ## The shortlist | # | Tool | Grade | Score | Best for | Price | Where | | --- | --- | --- | --- | --- | --- | --- | | 1 | [Hookdeck](https://www.anchorterminal.com/tools/hookdeck.md) | BB | 76.9 | Teams that receive third-party webhooks and want queueing, retries, replay and an agent that can inspect failures or pause a connection. | $39 / mo | hosted and local | | 2 | [Ably](https://www.anchorterminal.com/tools/ably.md) | BB | 75 | Fan-out of live messages to many connected clients, presence and resumable streams, with webhooks and queues as ways to get channel events to a backend. | $29 / mo | hosted | | 3 | [Svix](https://www.anchorterminal.com/tools/svix.md) | BB | 74 | A product that must send webhooks to its own customers with signing, retries, replay and a consumer portal, and an agent that builds or operates that integration. | $20 / mo | hosted | | 4 | [Amazon EventBridge](https://www.anchorterminal.com/tools/amazon-eventbridge.md) | BB | 73.7 | Teams already on AWS that want events routed between AWS services, their own code and outside HTTPS endpoints under IAM, with retention and replay on the bus. | $0.18 / GB | hosted | | 5 | [Upstash QStash](https://www.anchorterminal.com/tools/upstash-qstash.md) | BB | 72.3 | Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue. | $0.05 / GB | hosted | | 6 | [PubNub](https://www.anchorterminal.com/tools/pubnub.md) | B | 68.1 | Live fan-out to many connected clients with presence and history, and for an agent that manages a PubNub account through MCP. | $98 / mo | hosted and local | | 7 | [Hook0](https://www.anchorterminal.com/tools/hook0.md) | B | 64.6 | A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code. | Freemium | local | | 8 | [Centrifugo](https://www.anchorterminal.com/tools/centrifugo.md) | B | 63.1 | A team that wants to run its own realtime channel server and publish to browsers and apps from any backend, with history, recovery and presence. | Free · OSS | local | | 9 | [Convoy](https://www.anchorterminal.com/tools/convoy.md) | B | 62.2 | A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward. | $99 / mo | local | | 10 | [Webhook Relay](https://www.anchorterminal.com/tools/webhook-relay.md) | C | 57.8 | Teams that need third-party webhooks to reach localhost, on-premises CI or private Kubernetes services, with an agent that can configure buckets and inspect failed deliveries over MCP. | $8.99 / mo | hosted | ## Picks by need - Highest score overall: [Hookdeck](https://www.anchorterminal.com/tools/hookdeck.md), BB, 76.9/100 on the benchmark. Also [Ably](https://www.anchorterminal.com/tools/ably.md), BB, 75/100. - Reliability: [Convoy](https://www.anchorterminal.com/tools/convoy.md), 92/100 on reliability, against 90 for the overall leader. - Agent ergonomics: [Ably](https://www.anchorterminal.com/tools/ably.md), 87/100 on agent ergonomics, against 81 for the overall leader. - Security & auth: [Amazon EventBridge](https://www.anchorterminal.com/tools/amazon-eventbridge.md), 88/100 on security & auth, against 67 for the overall leader. - Maintenance & community: [Svix](https://www.anchorterminal.com/tools/svix.md), 88/100 on maintenance & community, against 74 for the overall leader. - Transparency & trust: [Amazon EventBridge](https://www.anchorterminal.com/tools/amazon-eventbridge.md), 87/100 on transparency & trust, against 76 for the overall leader. - A hosted MCP endpoint: [Upstash QStash](https://www.anchorterminal.com/tools/upstash-qstash.md), remote MCP server, nothing to install. - Self-hosting under an open licence: [Svix](https://www.anchorterminal.com/tools/svix.md), self-hosted, MIT for the server licence. Also [Hook0](https://www.anchorterminal.com/tools/hook0.md), self-hosted, SSPL-1 licence. ## How to choose - Retry schedule and limits: Check the retry schedule, attempt limit and when an event is marked failed, since a short limit can drop events a flaky endpoint would accept later. - Duplicates and event order: Check whether delivery is at least once or at most once, and whether order holds, so the agent knows if it must handle repeats itself. - Signature checks and replay: Check how signatures are verified and whether a failed event can be replayed from the delivery log, so an agent can trust what it receives. - Billing for retries: Check whether retries and failed attempts are billed, since a flaky endpoint can multiply the sends an agent pays for. - How the benchmark tests this category: The same thousand events sent through each listing to an endpoint that fails one request in ten. We check retries and their schedule, ordering, duplicate delivery, signature verification, replay of a failed event and the delivery log. In this run listings are graded from public evidence against the published checklist. ## Each one in detail ### 1. Hookdeck, BB 76.9/100 Hookdeck Event Gateway is a hosted service that receives webhooks, queues them and sends them on to HTTP destinations with filters, transformations, retries and replay. Agents use its REST API or the stdio MCP server in the Hookdeck CLI. - Verdict: API keys carry per-resource read or write scopes and can be rolled by API, and the MCP server starts read-only with annotations on every tool. The official Go SDK was last updated in December 2024 and the TypeScript SDK is deprecated. No audit log or prompt-injection guidance was found in the reviewed documentation. - Choose it for: Teams that receive third-party webhooks and want queueing, retries, replay and an agent that can inspect failures or pause a connection. - Strength: API keys take read or write scopes per resource family, project and resource grants, and rollover with a 0, 1 or 24 hour overlap - Strength: The MCP server registers 17 tools in read-only mode and 25 with `--allow-write`, each with readOnlyHint and destructiveHint set in the source - Strength: Public OpenAPI 3.0.1 spec with 135 operations, llms.txt and a Markdown version of every docs page - Weakness: Go SDK last committed 11 December 2024 and the TypeScript SDK is marked deprecated, so current clients are the CLI, Terraform and raw HTTP - Weakness: The MCP server is labelled beta, runs over stdio only and is not listed in the official MCP registry - Weakness: No idempotency key on REST writes. Safe retries depend on upsert by name with PUT - Price: $39 / mo · Auth: API key · x402: no · Where: hosted and local - Full assessment: https://www.anchorterminal.com/tools/hookdeck.md ### 2. Ably, BB 75/100 Hosted realtime messaging from Ably Realtime Ltd in London. Clients publish and subscribe on channels over WebSocket, SSE or MQTT, with a REST API, presence, message history, outbound and inbound webhooks, and AMQP queues. - Verdict: Pub/sub channels with per-channel capabilities on keys and tokens, idempotent publishing by message id, published limits for every plan and a 99.999 per cent SLA on paid plans. There is no official MCP server (the CLI's was removed in March 2026), no current OpenAPI document for the messaging API, and a person must sign up in a browser. - Choose it for: Fan-out of live messages to many connected clients, presence and resumable streams, with webhooks and queues as ways to get channel events to a backend. - Strength: API keys and tokens carry per-channel capabilities (publish, subscribe, history and 16 others), and tokens can be revoked by client, channel or revocation key - Strength: A message `id` or `X-Ably-MessageId` header makes a REST publish idempotent, and current SDKs set one by default - Strength: Limits are published per plan, including 50 HTTP requests a second on Free and 50 publishes a second per channel on every plan - Weakness: No official MCP server. The Ably CLI's built-in one was removed in v0.17.0 on 8 March 2026 - Weakness: The served OpenAPI document covers only the Control API (24 operations). The messaging REST API's spec sits in a repository marked deprecated in August 2024 - Weakness: Inbound webhooks and SSE put the API key or token in the URL query string - Price: $29 / mo · Auth: API key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/ably.md - Against #1: https://www.anchorterminal.com/compare/ably-vs-hookdeck.md ### 3. Svix, BB 74/100 Svix is a webhook sending service with a hosted REST API and an MIT-licensed server. One call creates a message, and Svix signs it, sends it to each subscribed endpoint, retries failures and logs every attempt. - Verdict: The hosted REST API has a public OpenAPI 3.1 spec with 141 operations, `Idempotency-Key` on 44 POST operations, and a published retry schedule of eight attempts. An API key can make any call for its environment, with no read-only or scoped key, and a person must create that key in the dashboard. - Choose it for: A product that must send webhooks to its own customers with signing, retries, replay and a consumer portal, and an agent that builds or operates that integration. - Strength: OpenAPI 3.1 spec with 141 operations, each described, and code samples on 140 of them - Strength: `Idempotency-Key` accepted on 44 POST operations, with the first result replayed for up to 12 hours - Strength: Published retry schedule of eight attempts over about 27.5 hours, with resend and recover calls for failed messages - Weakness: An API key can make any API call for its environment. No read-only or scoped API key was found in the reviewed documentation - Weakness: A person must create the first API key in the dashboard. No programmatic signup or key API was found - Weakness: 429 is in the spec for every operation, but no `Retry-After` header or backoff guidance was found, and the JavaScript SDK retries only on 5xx - Price: $20 / mo · Auth: API key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/svix.md - Against #1: https://www.anchorterminal.com/compare/hookdeck-vs-svix.md ### 4. Amazon EventBridge, BB 73.7/100 Amazon EventBridge is AWS's serverless event bus. Applications, AWS services and SaaS partners publish events, and the bus routes them to targets such as Lambda functions, SQS queues and HTTPS endpoints. It includes Pipes, a scheduler and a schema registry. - Verdict: IAM policies scope a credential to single actions and buses, and an SLA commits 99.99 per cent monthly uptime per Region. The Custom Event Bus API of 24 September 2026 adds retention, replay, ordering and publish-time deduplication. Classic `PutEvents` takes no idempotency token and answers 200 for a bus that does not exist. A person must open the AWS account. - Choose it for: Teams already on AWS that want events routed between AWS services, their own code and outside HTTPS endpoints under IAM, with retention and replay on the bus. - Strength: Smithy models published for both APIs, 57 Classic operations and 25 for the Custom Event Bus, with llms.txt and a Markdown twin of each guide page - Strength: 99.99 per cent monthly uptime commitment per Region under the Amazon EventBridge SLA, last updated 2 May 2022 - Strength: The Custom Event Bus keeps every event for 1 to 365 days, replays from a point in time, orders by event group and suppresses duplicates for 300 seconds - Weakness: Classic `PutEvents` has no idempotency token or deduplication, and failed entries come back inside a successful response for the caller to resend - Weakness: A Classic `PutEvents` call that names a bus that does not exist returns 200 and the event is dropped, per the user guide - Weakness: API destination connections carry Basic, OAuth client credentials or API key authorisation only. No request signature was found, and the target has 5 seconds to answer - Price: $0.18 / GB · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/amazon-eventbridge.md - Against #1: https://www.anchorterminal.com/compare/amazon-eventbridge-vs-hookdeck.md ### 5. Upstash QStash, BB 72.3/100 Upstash QStash is a hosted HTTP message queue and scheduler. A caller publishes a request to its REST API, and QStash sends it to a public URL with retries, delays, cron schedules, FIFO queues and signed requests. - Verdict: A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed. - Choose it for: Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue. - Strength: Public OpenAPI 3.1 file with 43 operations for messages, queues, schedules, URL groups, the dead letter queue, logs and signing keys - Strength: Retries default to 3 with exponential backoff capped at one day, and a destination's `Retry-After` header is honoured - Strength: `Upstash-Deduplication-Id` makes a repeated publish safe for 10 minutes, with 202 returned for a duplicate - Weakness: One full-access token and one read-only token per region. No per-queue or per-destination scopes were found - Weakness: The token is accepted as a `qstash_token` query parameter, which the webhook receiver guide relies on - Weakness: The Markdown pricing page says retries are free and, in its FAQ, that each retry is billed as a message - Price: $0.05 / GB · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/upstash-qstash.md - Against #1: https://www.anchorterminal.com/compare/hookdeck-vs-upstash-qstash.md ### 6. PubNub, B 68.1/100 Hosted realtime messaging from PubNub Inc. in San Francisco. Clients publish and subscribe on channels through SDKs or a REST API, with presence, message history, Functions and event forwarding to webhooks. An Admin API and an MCP server manage accounts. - Verdict: Pub/sub channels with a 17-tool MCP server on OAuth, an OpenAPI 3.1 Admin API with scoped, expiring keys, and a Markdown twin of every docs page. Publishes are not deduplicated, so a retry can duplicate a message. Access tokens travel in the URL query string, and the status page records a 20 minute global publish failure on 14 August 2026. - Choose it for: Live fan-out to many connected clients with presence and history, and for an agent that manages a PubNub account through MCP. - Strength: Hosted MCP server at `https://mcp.pubnub.com` with OAuth sign-in and 17 tools, and connections listed and revocable in the Admin Portal - Strength: The Admin API serves an OpenAPI 3.1 document (125 operations) with dated versions, a two-year version lifecycle and `Deprecation` and `Sunset` headers - Strength: Admin API keys are scoped by resource and by account, app or keyset, expire within one year and are shown once - Weakness: PubNub does not deduplicate publishes and has no idempotency key, so a retry after an unclear failure creates a second message - Weakness: The REST API carries the Access Manager token as the `auth` query parameter and the publish key in the URL path - Weakness: Access Manager is off by default. Without it, any holder of the publish and subscribe keys can use every channel on the keyset - Price: $98 / mo · Auth: OAuth or key · x402: no · Where: hosted and local - Full assessment: https://www.anchorterminal.com/tools/pubnub.md - Against #1: https://www.anchorterminal.com/compare/hookdeck-vs-pubnub.md ### 7. Hook0, B 64.6/100 Hook0 is a webhook sending service from FGRibreau SARL in France. An application posts events to a REST API and Hook0 signs, retries and logs deliveries to subscriber endpoints. It runs as an EU-hosted cloud or self-hosted under SSPL-1.0. - Verdict: Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise. - Choose it for: A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code. - Strength: Public OpenAPI 3.0 document at `/api/v1/swagger.json` with 56 operations, each with a summary, a description and ten error statuses - Strength: Service tokens are Biscuit tokens that the holder can narrow offline to one application, an expiry date or a read-only action list - Strength: Errors follow RFC 7807 with a stable `id`, and the reference lists 46 codes generated from the API's own `/errors` endpoint - Weakness: Six advisories were published between 6 August and 9 September 2026, including a High-rated SSRF in the delivery worker fixed on 11 August - Weakness: The status page records API and delivery downtime on 27 August and 22 September 2026, both traced to the hosting provider - Weakness: The terms give no uptime, latency or support commitment by default. Service levels exist only in a signed Enterprise agreement - Price: Freemium · Auth: API key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/hook0.md - Against #1: https://www.anchorterminal.com/compare/hook0-vs-hookdeck.md ### 8. Centrifugo, B 63.1/100 Centrifugo is an open-source, self-hosted realtime messaging server from Centrifugal Labs. A backend publishes to channels through its HTTP or gRPC server API, and subscribers receive messages over WebSocket, SSE, HTTP streaming or gRPC. - Verdict: Centrifugo is Apache-2.0 software an owner runs, with a 40-operation Swagger file, idempotency keys on publish and seven releases in the 90 days to 28 September 2026. The server API has one all-powerful key, which the docs also accept in the URL, and eleven security advisories were published between February and September 2026, two rated Critical. - Choose it for: A team that wants to run its own realtime channel server and publish to browsers and apps from any backend, with history, recovery and presence. - Strength: Apache-2.0 server with binaries for seven platforms, a Docker image, deb and rpm packages, a Helm chart and a Homebrew tap - Strength: Swagger 2.0 file and `api.proto` in the repository cover 40 server API operations, and the site serves llms.txt and a full Markdown corpus - Strength: `idempotency_key` on publish and broadcast drops duplicates for five minutes per channel on the Memory and Redis engines - Weakness: Two advisories in 2026 are rated Critical. One is an unauthenticated SSRF fixed in 6.7.0, the other an unauthenticated crash in the protobuf decoder - Weakness: The HTTP server API has one key for every method, set in the config file, with no scopes or read-only key in the open-source edition - Weakness: The docs accept the API key as an `api_key` URL query parameter, while recommending the `X-API-Key` header - Price: Free · OSS · Auth: API key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/centrifugo.md ### 9. Convoy, B 62.2/100 Convoy is a webhooks gateway from Frain Technologies. It sends outgoing webhooks with retries and signatures and receives incoming ones, through an HTTP API on Convoy Cloud or a self-hosted, source-available server. - Verdict: Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day. - Choose it for: A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward. - Strength: Public OpenAPI 3.0 spec with 68 operations, plus llms.txt and Markdown copies of every documentation page - Strength: Event creation accepts an `idempotency_key`, and the API has single and batch replay and retry endpoints for events and deliveries - Strength: Dated API versions (current default 2025-11-24) pinned per request with the `X-Convoy-Version` header - Weakness: Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8 - Weakness: Until v26.7.0 (4 August 2026) the events list returned endpoint secrets and custom auth headers in plaintext for dynamic events - Weakness: No security.txt and no SECURITY.md. The trust centre at trust.getconvoy.io renders only with JavaScript, so we couldn't read it - Price: $99 / mo · Auth: API key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/convoy.md - Against #1: https://www.anchorterminal.com/compare/convoy-vs-hookdeck.md ### 10. Webhook Relay, C 57.8/100 Webhook Relay is a hosted service that receives webhooks on a public URL and forwards them to public, private or localhost destinations, with filters, transformations and retries. Agents use its REST API, hosted MCP server or the `relay` CLI. - Verdict: Standalone access tokens carry a role and subscription scopes, and the hosted MCP server documents 40 tools that cover configuration, logs, retries and test sends. No API rate limit, deprecation policy or security.txt was found, the terms date from 2019 and the status page history could not be read. - Choose it for: Teams that need third-party webhooks to reach localhost, on-premises CI or private Kubernetes services, with an agent that can configure buckets and inspect failed deliveries over MCP. - Strength: Standalone tokens take a Viewer, Member, Billing or Admin role plus bucket and tunnel subscription scopes, and no token can create or change other tokens - Strength: Hosted MCP server at `https://my.webhookrelay.com/v1/mcp` with 40 documented tools, including `send_webhook` and `wait_for_webhook_log` for testing the real path - Strength: Durable retries per output with exponential backoff on schedules of about 25 minutes, 16 hours or 30 days - Weakness: No request rate limit for the management API was found in the reviewed documentation - Weakness: The terms of service were last updated on 25 November 2019 and the privacy statement on 1 June 2018. No DPA or deprecation policy was found - Weakness: The public changelog stops at server 0.179.20 of 23 May 2026 and CLI 1.34.4 of 8 August 2025 - Price: $8.99 / mo · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/webhook-relay.md - Against #1: https://www.anchorterminal.com/compare/hookdeck-vs-webhook-relay.md 1 more are ranked in the full table: https://www.anchorterminal.com/categories/webhooks.md ## Head to head - [Ably vs Hookdeck](https://www.anchorterminal.com/compare/ably-vs-hookdeck.md) - [Hookdeck vs Svix](https://www.anchorterminal.com/compare/hookdeck-vs-svix.md) - [Amazon EventBridge vs Hookdeck](https://www.anchorterminal.com/compare/amazon-eventbridge-vs-hookdeck.md) - [Hookdeck vs Upstash QStash](https://www.anchorterminal.com/compare/hookdeck-vs-upstash-qstash.md) - [Ably vs Svix](https://www.anchorterminal.com/compare/ably-vs-svix.md) - [Ably vs Amazon EventBridge](https://www.anchorterminal.com/compare/ably-vs-amazon-eventbridge.md) - [Ably vs Upstash QStash](https://www.anchorterminal.com/compare/ably-vs-upstash-qstash.md) - [Amazon EventBridge vs Svix](https://www.anchorterminal.com/compare/amazon-eventbridge-vs-svix.md) - [Svix vs Upstash QStash](https://www.anchorterminal.com/compare/svix-vs-upstash-qstash.md) - [Amazon EventBridge vs Upstash QStash](https://www.anchorterminal.com/compare/amazon-eventbridge-vs-upstash-qstash.md) ## Questions ### What are the highest-rated webhook and event delivery infrastructure for AI agents? Hookdeck has the highest benchmark score of the 11 ranked webhook and event delivery infrastructure, 76.9 (BB). Ably is second with 75 (BB). ### How many webhook and event delivery infrastructure are agent-ready? 5 of the 11 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark. ### Which webhook and event delivery infrastructure accept x402 payments? None of the ranked listings here accepts x402 for its main call yet. ### How is this list ranked? By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026. ## How this list is made The order is the Anchor benchmark score, the same number as on each listing. Each listing is graded from public evidence against the benchmark checklist, and the picks are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.