Head to head · Events webhooks send · October 2026 research run
Convoy vs Hook0
Hook0 scores 64.6 (B) on agent readiness against Convoy's 62.2 (B), and leads in 5 of 7 scored categories. Convoy leads on reliability. Both do events webhooks send.
Which one, for what
Convoy B
Good for A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.
Ahead on
- Reliability, 92 against 70
Watch for
Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8
Hook0 B
Good for A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code.
Ahead on
- Security & auth, 64 against 53
- Payments & pricing, 40 against 30
- Maintenance & community, 87 against 80
- Transparency & trust, 84 against 67
Also in its favour
- Runs on your own machine
Watch for
Six advisories were published between 6 August and 9 September 2026, including a High-rated SSRF in the delivery worker fixed on 11 August
Score by category
| Category | Weight this run | Convoy | Hook0 | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 92 | 70 | Convoy +22 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 78 | 79 | Hook0 +1 |
| Agent ergonomics | 13%16.2 | 69 | 65 | Convoy +4 |
| Security & auth | 14%17.5 | 53 | 64 | Hook0 +11 |
| Payments & pricing | 10%12.5 | 30 | 40 | Hook0 +10 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 80 | 87 | Hook0 +7 |
| Transparency & trust | 7%8.8 | 67 | 84 | Hook0 +17 |
| Negative events | ≤15 | -6 | -4 | |
| Total | 62.2 · B | 64.6 · B |
Facts side by side
| Fact | Convoy | Hook0 |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Frain Technologies Inc. | FGRibreau SARL |
| Hosted endpoint | no (local only) | no (local only) |
| Transports | HTTP | HTTP, stdio |
| Auth | API key | API key |
| Pricing | Paid | Freemium |
| x402 | no | no |
| Licence | Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use | SSPL-1.0 for the server (source available, not an OSI licence). The SDKs and the hook0-mcp server are MIT per crates.io and npm. Hook0 Cloud is a hosted service under Hook0's terms of service |
| Tools exposed | none | 23 |
| Read-only variant documented | no | yes |
| llms.txt | yes | yes |
| Last release | 2026-09-27 | 2026-09-21 |
| Terms last updated | 2026-06-27 | |
| Privacy policy last updated | 2023-06-01 | 2026-09-09 |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | yes | |
| Terms restrict benchmarking | not found in the text | |
| Terms or service can change without notice | yes | |
| Arbitration or class-action waiver | not found in the text | |
| Popularity | 2.9k stars, 2.3k npm/wk, 679 PyPI/wk | 1.5k stars, 507 npm/wk, 11 PyPI/wk |
Verdicts
Convoy
Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.
Hook0
Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise.
Before you call either
Convoy
- Use the regional base URL, https://us.getconvoy.cloud/api/v1 or https://eu.getconvoy.cloud/api/v1. A project key works only under /projects/{projectID}/
- Create an endpoint, then a subscription, then the event. An event sent to an endpoint with no subscription isn't dispatched
- Send
idempotency_keyon every event. A repeated key creates the event but no delivery, and the key stays reserved until retention deletes the event - Create projects with a personal API key and the
orgIDquery parameter. The project key in that response is shown once - Before retrying an endpoint or subscription create, list endpoints by
ownerId. Idempotency keys cover event ingestion only
Hook0
- Use a service token narrowed to one application and an expiry. A root service token covers the whole organisation, and an application secret can delete its application
- Send your own UUID as
event_idonPOST /api/v1/event/. A repeat returnsEventAlreadyIngested(409), which means the first call succeeded - Create the event type before sending. Unknown types fail with
EventTypeDoesNotExist, andlabels,occurred_atandpayload_content_typeare required - Send
payloadas a string, with JSON serialised inside it, up to 512 KiB - Set
HOOK0_API_URLforhook0-mcpto the origin without/api/v1, and setHOOK0_READ_ONLY=trueto hide the ten write tools
Questions
Which is better for AI agents, Convoy or Hook0?
Hook0 scores 64.6 (B) on agent readiness against Convoy's 62.2 (B), and leads in 5 of 7 scored categories. Convoy leads on reliability.
Do Convoy and Hook0 need an API key?
Both need an API key.
Can an agent call Convoy and Hook0 without installing anything?
No hosted endpoint is listed for Convoy. Hook0 runs on your own machine, with no hosted endpoint listed.
Other comparisons with Convoy or Hook0
Machine-readable
- This page as Markdown
/compare/convoy-vs-hook0.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/convoy.json·/api/v1/tools/hook0.json - From a terminal
anchor compare convoy hook0(the CLI) - Over MCP
compare_tools {"a": "convoy", "b": "hook0"}at/mcp, no key