{
  "data": {
    "a": {
      "slug": "convoy",
      "name": "Convoy",
      "vendor": "Frain Technologies Inc.",
      "vendorUrl": "https://www.getconvoy.io",
      "kind": "http-api",
      "category": "webhooks",
      "summary": "Convoy is a webhooks gateway from Frain Technologies. It sends outgoing webhooks with retries and signatures and receives incoming ones, through an HTTP API on Convoy Cloud or a self-hosted, source-available server.",
      "url": "https://www.anchorterminal.com/tools/convoy",
      "markdownUrl": "https://www.anchorterminal.com/tools/convoy.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/convoy.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/convoy.json",
      "repo": "https://github.com/frain-dev/convoy",
      "license": "Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "convoy.js"
        },
        {
          "registry": "pypi",
          "name": "convoy-python"
        },
        {
          "registry": "go",
          "name": "github.com/frain-dev/convoy-go/v2"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve API keys sent as a Bearer token. A project API key is scoped to one project and is returned once when the project is created, or regenerated in project settings. A personal API key, created in the dashboard's security settings, follows its user's organisation membership and creates projects. No OAuth for API clients and no partner or sales approval. On self-hosted instances `convoy bootstrap --with-api-key` prints a personal key.",
      "pricing": "paid",
      "pricingNotes": "Convoy Cloud has a 14-day trial without a card (one project, one user, 100 events a day), then Pro at $99 a month for 25 events a second or Premium at $499 a month. Plans are flat with a throughput limit and no per-message charge. The self-hosted Community edition is free with one user and two projects, and self-hosted Premium is $999 a month (https://www.getconvoy.io/pricing, checked 2026-10-08).",
      "priceSummary": "$99 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 2877,
        "npmWeekly": 2257,
        "pypiWeekly": 679,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.getconvoy.io/docs",
      "llmsTxt": "https://www.getconvoy.io/docs/llms.txt",
      "openapi": "https://raw.githubusercontent.com/frain-dev/convoy/main/docs/v3/openapi3.json",
      "capabilities": [
        "events.webhooks-send",
        "events.webhooks-receive"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "source-available",
        "webhooks",
        "api-key",
        "openapi",
        "llms-txt",
        "no-card",
        "status-page",
        "go",
        "python",
        "typescript",
        "ruby"
      ],
      "lastRelease": "2026-09-27",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.2,
        "grade": "B",
        "agentReady": false,
        "rank": 398,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 80,
          "payments": 30,
          "reliability": 92,
          "schema": 78,
          "security": 53,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -6,
        "negativeNotes": [
          "2026-07-24. Advisory GHSA-p5vg-v7mj-f6q4, rated High. Before v26.6.8 any caller authorised on one project could read another project's source record by id, including message broker credentials in plaintext. Patched in 26.6.8 and published by the maintainers, so the deduction is reduced to 4 (https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4).",
          "2026-08-04. Until v26.7.0 the events list returned `metadata` on dynamic events, which carried the endpoint secret and custom auth headers in plaintext. The field was removed across every API version and the change is documented, so the deduction is 2 (https://www.getconvoy.io/docs/api-reference/versioning)."
        ],
        "verdict": "Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.",
        "bestFor": "A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.",
        "strengths": [
          "Public OpenAPI 3.0 spec with 68 operations, plus llms.txt and Markdown copies of every documentation page",
          "Event creation accepts an `idempotency_key`, and the API has single and batch replay and retry endpoints for events and deliveries",
          "Dated API versions (current default 2025-11-24) pinned per request with the `X-Convoy-Version` header",
          "22 tagged releases between 27 June and 27 September 2026, with breaking changes listed per release in CHANGELOG.md",
          "Convoy Cloud's upgrade policy promises at least 180 days' notice of major upgrades and deprecations"
        ],
        "weaknesses": [
          "Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8",
          "Until v26.7.0 (4 August 2026) the events list returned endpoint secrets and custom auth headers in plaintext for dynamic events",
          "No security.txt and no SECURITY.md. The trust centre at trust.getconvoy.io renders only with JavaScript, so we couldn't read it",
          "The errors page documents four HTTP codes and one sample body. 429 and Retry-After aren't in the API reference",
          "Cloud needs a browser signup, and the 14-day trial allows 100 events a day, one project and one user"
        ],
        "agentNotes": [
          "Use the regional base URL, https://us.getconvoy.cloud/api/v1 or https://eu.getconvoy.cloud/api/v1. A project key works only under /projects/{projectID}/",
          "Create an endpoint, then a subscription, then the event. An event sent to an endpoint with no subscription isn't dispatched",
          "Send `idempotency_key` on every event. A repeated key creates the event but no delivery, and the key stays reserved until retention deletes the event",
          "Create projects with a personal API key and the `orgID` query parameter. The project key in that response is shown once",
          "Before retrying an endpoint or subscription create, list endpoints by `ownerId`. Idempotency keys cover event ingestion only"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.2
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 80,
          "payments": 30,
          "reliability": 92,
          "schema": 78,
          "security": 53,
          "transparency": 65
        },
        "provenanceScore": 69
      },
      "connect": {
        "install": "curl -fsSL https://getconvoy.io/install | bash",
        "http": "curl --request POST \\\n  --url https://{region}.getconvoy.cloud/api/v1/projects/\u003cproject-id\u003e/events \\\n  --header 'Authorization: Bearer \u003capi-key\u003e' \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"endpoint_id\": \"\u003cendpoint-id\u003e\", \"event_type\": \"payment.success\", \"data\": {\"status\": \"Completed\"}}'"
      },
      "letme": {
        "capability": "https://letme.dev/events.webhooks-send",
        "tool": "https://letme.dev/convoy"
      },
      "area": "developer",
      "unitPrices": [
        {
          "item": "Cloud Pro",
          "unit": "month",
          "usd": 99,
          "note": "25 events a second, 7-day retention"
        },
        {
          "item": "Cloud Premium",
          "unit": "month",
          "usd": 499,
          "note": "custom rate limits and retention"
        },
        {
          "item": "Self-hosted Premium licence",
          "unit": "month",
          "usd": 999,
          "note": "Community edition is free"
        }
      ],
      "provenance": {
        "legalEntity": "Frain Technologies Inc.",
        "domain": "getconvoy.io",
        "domainRegistered": "2021-09-06",
        "endpointOnVendorDomain": false,
        "terms": "https://www.getconvoy.io/legal/Terms-of-Use-Convoy.pdf",
        "privacy": "https://www.getconvoy.io/legal/privacy-policy",
        "statusPage": "https://status.getconvoy.io",
        "changelog": "https://github.com/frain-dev/convoy/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The repository's LICENSE file names Frain Technologies Inc. as licensor, and the home page footer names Frain Technologies at 2261 Market Street, San Francisco, CA 94114. The terms and privacy notice say only Convoy and its affiliates, with info@frain.dev as contact.",
          "The Cloud API answers at us.getconvoy.cloud and eu.getconvoy.cloud, a different registered domain from getconvoy.io. The vendor's own docs and OpenAPI spec name both hosts.",
          "www.getconvoy.io/.well-known/security.txt returns 404. us.getconvoy.cloud returns the dashboard's HTML at that path. The GitHub repository has no SECURITY.md but accepts private vulnerability reports.",
          "The privacy notice is dated 1 June 2023. The DPA at getconvoy.io/legal/dpa points to a sub-processor list at trust.getconvoy.io/subprocessors, which renders only with JavaScript and which we couldn't read.",
          "RDAP for getconvoy.io gives a registration date of 2021-09-06."
        ],
        "score": 69
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/convoy.json",
      "live": {
        "slug": "convoy",
        "vendorStatus": {
          "page": "https://status.getconvoy.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T09:25:00.012737748Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "frain-dev/convoy",
            "version": "v26.8.0",
            "released": "2026-09-28",
            "seenAt": "2026-10-08T16:07:07.309156702Z"
          },
          {
            "registry": "npm",
            "name": "convoy.js",
            "version": "1.1.0",
            "seenAt": "2026-10-08T16:07:02.917445318Z"
          },
          {
            "registry": "pypi",
            "name": "convoy-python",
            "version": "0.2.0",
            "released": "2023-05-16",
            "seenAt": "2026-10-08T16:07:07.117567905Z"
          }
        ],
        "githubStars": 2877,
        "npmWeekly": 2257,
        "pypiWeekly": 679,
        "securityTxt": {
          "url": "https://getconvoy.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:08.354465852Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/frain-dev/convoy/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:09.887860175Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "91084795c305"
          },
          {
            "url": "https://www.getconvoy.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:58.163197054Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "63dc1731ded0"
          },
          {
            "url": "https://www.getconvoy.io/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:55.875642867Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2ffdcb5dca1d"
          }
        ],
        "updatedAt": "2026-10-09T09:25:00.012737748Z"
      }
    },
    "answer": "Hook0 scores 64.6 (B) on agent readiness against Convoy's 62.2 (B), and leads in 5 of 7 scored categories. Convoy leads on reliability.",
    "b": {
      "slug": "hook0",
      "name": "Hook0",
      "vendor": "FGRibreau SARL",
      "vendorUrl": "https://www.hook0.com",
      "kind": "http-api",
      "category": "webhooks",
      "summary": "Hook0 is a webhook sending service from FGRibreau SARL in France. An application posts events to a REST API and Hook0 signs, retries and logs deliveries to subscriber endpoints. It runs as an EU-hosted cloud or self-hosted under SSPL-1.0.",
      "url": "https://www.anchorterminal.com/tools/hook0",
      "markdownUrl": "https://www.anchorterminal.com/tools/hook0.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hook0.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hook0.json",
      "repo": "https://github.com/hook0/hook0",
      "license": "SSPL-1.0 for the server (source available, not an OSI licence). The SDKs and the `hook0-mcp` server are MIT per crates.io and npm. Hook0 Cloud is a hosted service under Hook0's terms of service",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "hook0-client"
        },
        {
          "registry": "pypi",
          "name": "hook0-client"
        },
        {
          "registry": "cargo",
          "name": "hook0-mcp"
        }
      ],
      "auth": "api-key",
      "authNotes": "Every call takes `Authorization: Bearer \u003ctoken\u003e` at https://app.hook0.com/api/v1. A person signs up in a browser, passes a Cloudflare Turnstile check and verifies an email address, then creates a service token in the dashboard. Service tokens are Biscuit tokens scoped to one organisation, and the holder can narrow one offline to a single application, an expiry date or an allowlist of actions. Each application also has secrets that work as Bearer tokens with full control of that application. No OAuth for API clients.",
      "pricing": "freemium",
      "pricingNotes": "Free Developer plan with no card, 100 events a day, one application and 7 days of retention, and a 429 once the quota is used. Startup is €59 a month for 30,000 events a day, then €0.003 an event. Pro is €190 a month for 100,000 events a day, then €0.0001 an event. Prices exclude VAT and are published in euros only. Subscriptions and retries aren't counted. Self-hosting is free, and a managed on-premise instance is €500 a month plus €1,000 setup (checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the OpenAPI document, the repository or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 23,
      "popularity": {
        "githubStars": 1494,
        "npmWeekly": 507,
        "pypiWeekly": 11,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://documentation.hook0.com/",
      "llmsTxt": "https://documentation.hook0.com/llms.txt",
      "openapi": "https://app.hook0.com/api/v1/swagger.json",
      "capabilities": [
        "events.webhooks-send"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "source-available",
        "webhooks",
        "api-key",
        "openapi",
        "llms-txt",
        "mcp",
        "free-tier",
        "no-card",
        "status-page",
        "eu-hosted",
        "typescript",
        "python",
        "rust",
        "go"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.6,
        "grade": "B",
        "agentReady": false,
        "rank": 313,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 40,
          "reliability": 70,
          "schema": 79,
          "security": 64,
          "transparency": 84
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-08-11. Server-side request forgery in the delivery worker, rated High by the vendor. An IPv6 transition address passed the filter on forbidden targets, so a tenant could make the worker reach internal addresses. Fixed in commit 3b27e932 and published with the reporter credited, so the deduction is reduced to 3 (https://documentation.hook0.com/resources/security-advisories).",
          "2026-08-24. A password reset link stayed usable after it had reset a password, rated Medium, which allowed account takeover by anyone holding a spent link. Fixed in commit 80fae0de and published, so the deduction is 1 (https://documentation.hook0.com/resources/security-advisories)."
        ],
        "verdict": "Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise.",
        "bestFor": "A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code.",
        "strengths": [
          "Public OpenAPI 3.0 document at `/api/v1/swagger.json` with 56 operations, each with a summary, a description and ten error statuses",
          "Service tokens are Biscuit tokens that the holder can narrow offline to one application, an expiry date or a read-only action list",
          "Errors follow RFC 7807 with a stable `id`, and the reference lists 46 codes generated from the API's own `/errors` endpoint",
          "Free Developer plan of 100 events a day with no card, and per-event overage prices published for both paid plans",
          "Retention by plan, sub-processors with countries, a DPA, a GDPR Article 30 register and a transfer impact assessment are all public"
        ],
        "weaknesses": [
          "Six advisories were published between 6 August and 9 September 2026, including a High-rated SSRF in the delivery worker fixed on 11 August",
          "The status page records API and delivery downtime on 27 August and 22 September 2026, both traced to the hosting provider",
          "The terms give no uptime, latency or support commitment by default. Service levels exist only in a signed Enterprise agreement",
          "Cloud registration requires a Cloudflare Turnstile token and email verification, so an agent can't create an account alone",
          "The API introduction page documents an error shape and `limit` and `offset` pagination that the OpenAPI document doesn't contain"
        ],
        "agentNotes": [
          "Use a service token narrowed to one application and an expiry. A root service token covers the whole organisation, and an application secret can delete its application",
          "Send your own UUID as `event_id` on `POST /api/v1/event/`. A repeat returns `EventAlreadyIngested` (409), which means the first call succeeded",
          "Create the event type before sending. Unknown types fail with `EventTypeDoesNotExist`, and `labels`, `occurred_at` and `payload_content_type` are required",
          "Send `payload` as a string, with JSON serialised inside it, up to 512 KiB",
          "Set `HOOK0_API_URL` for `hook0-mcp` to the origin without `/api/v1`, and set `HOOK0_READ_ONLY=true` to hide the ten write tools"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.6
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 40,
          "reliability": 70,
          "schema": 79,
          "security": 64,
          "transparency": 76
        },
        "provenanceScore": 91
      },
      "connect": {
        "install": "cargo install hook0-mcp",
        "http": "curl -X POST \"https://app.hook0.com/api/v1/event\" \\\n  -H \"Authorization: Bearer $HOOK0_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"application_id\": \"\u003capplication-id\u003e\", \"event_type\": \"user.account.created\", \"payload\": \"{\\\"user_id\\\": 123}\", \"payload_content_type\": \"application/json\", \"labels\": {\"environment\": \"tutorial\"}, \"occurred_at\": \"2026-10-08T12:00:00Z\"}'",
        "config": {
          "mcpServers": {
            "hook0": {
              "command": "hook0-mcp",
              "env": {
                "HOOK0_API_TOKEN": "your-service-token-here"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/events.webhooks-send",
        "tool": "https://letme.dev/hook0"
      },
      "area": "developer",
      "provenance": {
        "legalEntity": "FGRibreau SARL",
        "domain": "hook0.com",
        "domainRegistered": "2020-09-02",
        "endpointOnVendorDomain": true,
        "terms": "https://www.hook0.com/terms",
        "privacy": "https://www.hook0.com/privacy-policy",
        "statusPage": "https://status.hook0.com",
        "changelog": "https://gitlab.com/hook0/hook0/-/releases",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last updated 27 June 2026) name FGRibreau SARL, a French limited liability company registered at La Roche-sur-Yon under number 850 824 350, with its office at 3 rue de l'Aubepine, 85110 Chantonnay, France.",
          "The API answers at app.hook0.com, a hook0.com subdomain, per the OpenAPI document's server entry.",
          "www.hook0.com/.well-known/security.txt names security@hook0.com, a disclosure policy and an acknowledgments page, and expires on 6 August 2027.",
          "The privacy policy (last updated 9 September 2026) covers the Hook0 service and lists sub-processors with countries. A data processing addendum is published at www.hook0.com/data-processing-addendum.",
          "The documentation's changelog page only links to GitHub Releases. Releases are tagged per component on GitLab, where development happens, and each component keeps a CHANGELOG.md.",
          "RDAP for hook0.com gives a registration date of 2020-09-02."
        ],
        "score": 91
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hook0.json",
      "live": {
        "slug": "hook0",
        "vendorStatus": {
          "page": "https://status.hook0.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:03.331943028Z"
        },
        "updatedAt": "2026-10-09T07:58:03.331943028Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Frain Technologies Inc.",
        "b": "FGRibreau SARL",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use",
        "b": "SSPL-1.0 for the server (source available, not an OSI licence). The SDKs and the `hook0-mcp` server are MIT per crates.io and npm. Hook0 Cloud is a hosted service under Hook0's terms of service",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "23",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-27",
        "b": "2026-09-21",
        "name": "Last release"
      },
      {
        "a": "",
        "b": "2026-06-27",
        "name": "Terms last updated"
      },
      {
        "a": "2023-06-01",
        "b": "2026-09-09",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "2.9k stars, 2.3k npm/wk, 679 PyPI/wk",
        "b": "1.5k stars, 507 npm/wk, 11 PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Hook0 scores 64.6 (B) on agent readiness against Convoy's 62.2 (B), and leads in 5 of 7 scored categories. Convoy leads on reliability.",
        "question": "Which is better for AI agents, Convoy or Hook0?"
      },
      {
        "answer": "Both need an API key.",
        "question": "Do Convoy and Hook0 need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Convoy. Hook0 runs on your own machine, with no hosted endpoint listed.",
        "question": "Can an agent call Convoy and Hook0 without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 92 against 70"
        ],
        "also": null,
        "goodFor": "A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.",
        "slug": "convoy",
        "watchFor": "Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 64 against 53",
          "Payments \u0026 pricing, 40 against 30",
          "Maintenance \u0026 community, 87 against 80",
          "Transparency \u0026 trust, 84 against 67"
        ],
        "also": [
          "Runs on your own machine"
        ],
        "goodFor": "A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code.",
        "slug": "hook0",
        "watchFor": "Six advisories were published between 6 August and 9 September 2026, including a High-rated SSRF in the delivery worker fixed on 11 August"
      }
    ],
    "job": {
      "capability": "events.webhooks-send",
      "name": "Events webhooks send"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/ably-vs-convoy.json",
        "title": "Ably vs Convoy",
        "url": "https://www.anchorterminal.com/compare/ably-vs-convoy"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ably-vs-hook0.json",
        "title": "Ably vs Hook0",
        "url": "https://www.anchorterminal.com/compare/ably-vs-hook0"
      },
      {
        "json": "https://www.anchorterminal.com/compare/convoy-vs-hookdeck.json",
        "title": "Convoy vs Hookdeck",
        "url": "https://www.anchorterminal.com/compare/convoy-vs-hookdeck"
      },
      {
        "json": "https://www.anchorterminal.com/compare/convoy-vs-pusher-channels.json",
        "title": "Convoy vs Pusher Channels",
        "url": "https://www.anchorterminal.com/compare/convoy-vs-pusher-channels"
      },
      {
        "json": "https://www.anchorterminal.com/compare/convoy-vs-svix.json",
        "title": "Convoy vs Svix",
        "url": "https://www.anchorterminal.com/compare/convoy-vs-svix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash.json",
        "title": "Convoy vs Upstash QStash",
        "url": "https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hook0-vs-hookdeck.json",
        "title": "Hook0 vs Hookdeck",
        "url": "https://www.anchorterminal.com/compare/hook0-vs-hookdeck"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hook0-vs-pusher-channels.json",
        "title": "Hook0 vs Pusher Channels",
        "url": "https://www.anchorterminal.com/compare/hook0-vs-pusher-channels"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hook0-vs-svix.json",
        "title": "Hook0 vs Svix",
        "url": "https://www.anchorterminal.com/compare/hook0-vs-svix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hook0-vs-upstash-qstash.json",
        "title": "Hook0 vs Upstash QStash",
        "url": "https://www.anchorterminal.com/compare/hook0-vs-upstash-qstash"
      }
    ],
    "scores": [
      {
        "by": 22,
        "convoy": 92,
        "edge": "convoy",
        "hook0": 70,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "convoy": 78,
        "edge": "hook0",
        "hook0": 79,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 4,
        "convoy": 69,
        "edge": "convoy",
        "hook0": 65,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 11,
        "convoy": 53,
        "edge": "hook0",
        "hook0": 64,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 10,
        "convoy": 30,
        "edge": "hook0",
        "hook0": 40,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "convoy": 80,
        "edge": "hook0",
        "hook0": 87,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 17,
        "convoy": 67,
        "edge": "hook0",
        "hook0": 84,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Hook0 scores 64.6 (B) on agent readiness against Convoy's 62.2 (B), and leads in 5 of 7 scored categories. Convoy leads on reliability. Both do events webhooks send.",
    "verdicts": {
      "convoy": "Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.",
      "hook0": "Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/convoy-vs-hook0",
    "json": "https://www.anchorterminal.com/compare/convoy-vs-hook0.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/convoy-vs-hook0.md",
    "slim": "https://www.anchorterminal.com/compare/convoy-vs-hook0.min.md"
  },
  "markdown": "Hook0 scores 64.6 (B) on agent readiness against Convoy's 62.2 (B), and leads in 5 of 7 scored categories. Convoy leads on reliability. Both do events webhooks send.\n\n- Convoy: grade B, 62.2/100, rank #398 of 842. Markdown https://www.anchorterminal.com/tools/convoy.md · JSON https://www.anchorterminal.com/api/v1/tools/convoy.json\n- Hook0: grade B, 64.6/100, rank #313 of 842. Markdown https://www.anchorterminal.com/tools/hook0.md · JSON https://www.anchorterminal.com/api/v1/tools/hook0.json\n\n## Which one, for what\n\n### Convoy (B)\n\nGood for: A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.\n\nAhead on:\n- Reliability, 92 against 70\n\nWatch for: Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8\n\n### Hook0 (B)\n\nGood for: A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code.\n\nAhead on:\n- Security \u0026 auth, 64 against 53\n- Payments \u0026 pricing, 40 against 30\n- Maintenance \u0026 community, 87 against 80\n- Transparency \u0026 trust, 84 against 67\n\nAlso in its favour:\n- Runs on your own machine\n\nWatch for: Six advisories were published between 6 August and 9 September 2026, including a High-rated SSRF in the delivery worker fixed on 11 August\n\n\n## Score by category\n\n| Category | Weight | Convoy | Hook0 | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 92 | 70 | Convoy +22 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 78 | 79 | Hook0 +1 |\n| Agent ergonomics | 13% (16.2 this run) | 69 | 65 | Convoy +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 53 | 64 | Hook0 +11 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 40 | Hook0 +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 87 | Hook0 +7 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 67 | 84 | Hook0 +17 |\n| Negative events | ≤15 | -6 | -4 | |\n| **Total** | | **62.2 · B** | **64.6 · B** | |\n\n## Facts side by side\n\n| Fact | Convoy | Hook0 |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Frain Technologies Inc. | FGRibreau SARL |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP, stdio |\n| Auth | API key | API key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use | SSPL-1.0 for the server (source available, not an OSI licence). The SDKs and the `hook0-mcp` server are MIT per crates.io and npm. Hook0 Cloud is a hosted service under Hook0's terms of service |\n| Tools exposed | none | 23 |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| Last release | 2026-09-27 | 2026-09-21 |\n| Terms last updated |  | 2026-06-27 |\n| Privacy policy last updated | 2023-06-01 | 2026-09-09 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | yes |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | yes |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 2.9k stars, 2.3k npm/wk, 679 PyPI/wk | 1.5k stars, 507 npm/wk, 11 PyPI/wk |\n\n## Verdicts\n\n**Convoy.** Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.\n\n**Hook0.** Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise.\n\n## Before you call either\n\n### Convoy\n\n1. Use the regional base URL, https://us.getconvoy.cloud/api/v1 or https://eu.getconvoy.cloud/api/v1. A project key works only under /projects/{projectID}/\n2. Create an endpoint, then a subscription, then the event. An event sent to an endpoint with no subscription isn't dispatched\n3. Send `idempotency_key` on every event. A repeated key creates the event but no delivery, and the key stays reserved until retention deletes the event\n4. Create projects with a personal API key and the `orgID` query parameter. The project key in that response is shown once\n5. Before retrying an endpoint or subscription create, list endpoints by `ownerId`. Idempotency keys cover event ingestion only\n\n### Hook0\n\n1. Use a service token narrowed to one application and an expiry. A root service token covers the whole organisation, and an application secret can delete its application\n2. Send your own UUID as `event_id` on `POST /api/v1/event/`. A repeat returns `EventAlreadyIngested` (409), which means the first call succeeded\n3. Create the event type before sending. Unknown types fail with `EventTypeDoesNotExist`, and `labels`, `occurred_at` and `payload_content_type` are required\n4. Send `payload` as a string, with JSON serialised inside it, up to 512 KiB\n5. Set `HOOK0_API_URL` for `hook0-mcp` to the origin without `/api/v1`, and set `HOOK0_READ_ONLY=true` to hide the ten write tools\n\n## Questions\n\n### Which is better for AI agents, Convoy or Hook0?\n\nHook0 scores 64.6 (B) on agent readiness against Convoy's 62.2 (B), and leads in 5 of 7 scored categories. Convoy leads on reliability.\n\n### Do Convoy and Hook0 need an API key?\n\nBoth need an API key.\n\n### Can an agent call Convoy and Hook0 without installing anything?\n\nNo hosted endpoint is listed for Convoy. Hook0 runs on your own machine, with no hosted endpoint listed.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/convoy-vs-hook0.json, and with the fewest tokens: https://www.anchorterminal.com/compare/convoy-vs-hook0.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"convoy\", \"b\": \"hook0\"}`. From a terminal: `anchor compare convoy hook0`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/convoy.json and https://www.anchorterminal.com/api/v1/tools/hook0.json\n\n## Other comparisons with Convoy or Hook0\n\n- [Ably vs Convoy](https://www.anchorterminal.com/compare/ably-vs-convoy.md)\n- [Ably vs Hook0](https://www.anchorterminal.com/compare/ably-vs-hook0.md)\n- [Convoy vs Hookdeck](https://www.anchorterminal.com/compare/convoy-vs-hookdeck.md)\n- [Convoy vs Pusher Channels](https://www.anchorterminal.com/compare/convoy-vs-pusher-channels.md)\n- [Convoy vs Svix](https://www.anchorterminal.com/compare/convoy-vs-svix.md)\n- [Convoy vs Upstash QStash](https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash.md)\n- [Hook0 vs Hookdeck](https://www.anchorterminal.com/compare/hook0-vs-hookdeck.md)\n- [Hook0 vs Pusher Channels](https://www.anchorterminal.com/compare/hook0-vs-pusher-channels.md)\n- [Hook0 vs Svix](https://www.anchorterminal.com/compare/hook0-vs-svix.md)\n- [Hook0 vs Upstash QStash](https://www.anchorterminal.com/compare/hook0-vs-upstash-qstash.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Convoy vs Hook0",
        "url": ""
      }
    ],
    "description": "Hook0 scores 64.6 (B) on agent readiness against Convoy's 62.2 (B), and leads in 5 of 7 scored categories. Convoy leads on reliability. Both do events webhooks send. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Convoy B 62.2",
      "Hook0 B 64.6",
      "scores"
    ],
    "h1": "Convoy vs Hook0",
    "image": "https://www.anchorterminal.com/assets/og/compare-convoy-vs-hook0.png",
    "path": "/compare/convoy-vs-hook0",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Convoy vs Hook0 for AI agents, B 62.2 vs B 64.6 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/convoy-vs-hook0"
  },
  "tokens": {
    "markdown": 2100,
    "slim": 730
  },
  "version": 1
}
