Head to head · Events webhooks send · October 2026 research run
Convoy vs Upstash QStash
Upstash QStash scores 72.3 (BB) on agent readiness against Convoy's 62.2 (B), and leads in 4 of 7 scored categories. Convoy leads on reliability. Both do events webhooks send.
Which one, for what
Convoy B
Good for A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.
Ahead on
- Reliability, 92 against 83
Watch for
Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8
Good for Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.
Ahead on
- Agent ergonomics, 83 against 69
- Security & auth, 61 against 53
- Payments & pricing, 40 against 30
- Transparency & trust, 81 against 67
Also in its favour
- Agent-ready, a grade of BB or better
- A hosted endpoint, with nothing to install
- No incidents deducted, where Convoy loses 6 points for them
Watch for
One full-access token and one read-only token per region. No per-queue or per-destination scopes were found
Score by category
| Category | Weight this run | Convoy | Upstash QStash | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 92 | 83 | Convoy +9 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 78 | 78 | even |
| Agent ergonomics | 13%16.2 | 69 | 83 | Upstash QStash +14 |
| Security & auth | 14%17.5 | 53 | 61 | Upstash QStash +8 |
| Payments & pricing | 10%12.5 | 30 | 40 | Upstash QStash +10 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 80 | 77 | Convoy +3 |
| Transparency & trust | 7%8.8 | 67 | 81 | Upstash QStash +14 |
| Negative events | ≤15 | -6 | 0 | |
| Total | 62.2 · B | 72.3 · BB |
Facts side by side
| Fact | Convoy | Upstash QStash |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Frain Technologies Inc. | Upstash |
| Hosted endpoint | no (local only) | https://qstash.upstash.io/v2 |
| Transports | HTTP | HTTP, Streamable HTTP |
| Auth | API key | OAuth or key |
| Pricing | Paid | Freemium |
| x402 | no | no |
| Licence | Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use | Proprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT |
| Tools exposed | none | 10 |
| Read-only variant documented | no | yes |
| llms.txt | yes | yes |
| MCP registry | not listed | io.github.upstash/mcp-server |
| Last release | 2026-09-27 | 2026-09-29 |
| Terms last updated | ||
| Privacy policy last updated | 2023-06-01 | |
| Customer content may train models | ||
| Terms restrict automated access | ||
| Terms restrict benchmarking | ||
| Terms or service can change without notice | ||
| Arbitration or class-action waiver | ||
| Popularity | 2.9k stars, 2.3k npm/wk, 679 PyPI/wk | 269 stars, 816k npm/wk, 91k PyPI/wk |
Verdicts
Convoy
Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.
Upstash QStash
A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed.
Before you call either
Convoy
- Use the regional base URL, https://us.getconvoy.cloud/api/v1 or https://eu.getconvoy.cloud/api/v1. A project key works only under /projects/{projectID}/
- Create an endpoint, then a subscription, then the event. An event sent to an endpoint with no subscription isn't dispatched
- Send
idempotency_keyon every event. A repeated key creates the event but no delivery, and the key stays reserved until retention deletes the event - Create projects with a personal API key and the
orgIDquery parameter. The project key in that response is shown once - Before retrying an endpoint or subscription create, list endpoints by
ownerId. Idempotency keys cover event ingestion only
Upstash QStash
- Use the regional host that matches the token.
qstash.upstash.iois the EU region, and US tokens work only onqstash-us-east-1.upstash.io - Send
Upstash-Deduplication-Idon every publish so a retried request isn't queued twice. The window is 10 minutes - Budget for retries. Per the pricing FAQ each delivery attempt is billed as a message, so set
Upstash-Retriesdeliberately - Give monitoring agents the read-only token, and set
Upstash-Redact-Fieldson publish, because that token still reads message bodies and headers - Make the destination idempotent on
Upstash-Message-Id. Delivery is at least once, and duplicates can follow a server restart
Questions
Which is better for AI agents, Convoy or Upstash QStash?
Upstash QStash scores 72.3 (BB) on agent readiness against Convoy's 62.2 (B), and leads in 4 of 7 scored categories. Convoy leads on reliability.
Do Convoy and Upstash QStash need an API key?
Convoy needs an API key. Upstash QStash takes an API key or an OAuth sign-in.
Can an agent call Convoy and Upstash QStash without installing anything?
No hosted endpoint is listed for Convoy. Upstash QStash has a hosted endpoint at https://qstash.upstash.io/v2.
Other comparisons with Convoy or Upstash QStash
Machine-readable
- This page as Markdown
/compare/convoy-vs-upstash-qstash.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/convoy.json·/api/v1/tools/upstash-qstash.json - From a terminal
anchor compare convoy upstash-qstash(the CLI) - Over MCP
compare_tools {"a": "convoy", "b": "upstash-qstash"}at/mcp, no key