Head to head · Events webhooks send · October 2026 research run

Convoy vs Upstash QStash

Upstash QStash scores 72.3 (BB) on agent readiness against Convoy's 62.2 (B), and leads in 4 of 7 scored categories. Convoy leads on reliability. Both do events webhooks send.

Which one, for what

Convoy B

Good for A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.

Ahead on

  • Reliability, 92 against 83

Watch for

Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8

Upstash QStash BB

Good for Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.

Ahead on

  • Agent ergonomics, 83 against 69
  • Security & auth, 61 against 53
  • Payments & pricing, 40 against 30
  • Transparency & trust, 81 against 67

Also in its favour

  • Agent-ready, a grade of BB or better
  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Convoy loses 6 points for them

Watch for

One full-access token and one read-only token per region. No per-queue or per-destination scopes were found

Score by category

CategoryWeight this runConvoyUpstash QStashEdge
Reliability16%209283Convoy +9
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27878even
Agent ergonomics13%16.26983Upstash QStash +14
Security & auth14%17.55361Upstash QStash +8
Payments & pricing10%12.53040Upstash QStash +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88077Convoy +3
Transparency & trust7%8.86781Upstash QStash +14
Negative events≤15-60
Total62.2 · B72.3 · BB

Facts side by side

FactConvoyUpstash QStash
KindHTTP APIHTTP API
VendorFrain Technologies Inc.Upstash
Hosted endpointno (local only)https://qstash.upstash.io/v2
TransportsHTTPHTTP, Streamable HTTP
AuthAPI keyOAuth or key
PricingPaidFreemium
x402nono
LicenceElastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of useProprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT
Tools exposednone10
Read-only variant documentednoyes
llms.txtyesyes
MCP registrynot listedio.github.upstash/mcp-server
Last release2026-09-272026-09-29
Terms last updated
Privacy policy last updated2023-06-01
Customer content may train models
Terms restrict automated access
Terms restrict benchmarking
Terms or service can change without notice
Arbitration or class-action waiver
Popularity2.9k stars, 2.3k npm/wk, 679 PyPI/wk269 stars, 816k npm/wk, 91k PyPI/wk

Verdicts

Convoy

Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.

Upstash QStash

A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed.

Before you call either

Convoy

  1. Use the regional base URL, https://us.getconvoy.cloud/api/v1 or https://eu.getconvoy.cloud/api/v1. A project key works only under /projects/{projectID}/
  2. Create an endpoint, then a subscription, then the event. An event sent to an endpoint with no subscription isn't dispatched
  3. Send idempotency_key on every event. A repeated key creates the event but no delivery, and the key stays reserved until retention deletes the event
  4. Create projects with a personal API key and the orgID query parameter. The project key in that response is shown once
  5. Before retrying an endpoint or subscription create, list endpoints by ownerId. Idempotency keys cover event ingestion only

Upstash QStash

  1. Use the regional host that matches the token. qstash.upstash.io is the EU region, and US tokens work only on qstash-us-east-1.upstash.io
  2. Send Upstash-Deduplication-Id on every publish so a retried request isn't queued twice. The window is 10 minutes
  3. Budget for retries. Per the pricing FAQ each delivery attempt is billed as a message, so set Upstash-Retries deliberately
  4. Give monitoring agents the read-only token, and set Upstash-Redact-Fields on publish, because that token still reads message bodies and headers
  5. Make the destination idempotent on Upstash-Message-Id. Delivery is at least once, and duplicates can follow a server restart

Questions

Which is better for AI agents, Convoy or Upstash QStash?

Upstash QStash scores 72.3 (BB) on agent readiness against Convoy's 62.2 (B), and leads in 4 of 7 scored categories. Convoy leads on reliability.

Do Convoy and Upstash QStash need an API key?

Convoy needs an API key. Upstash QStash takes an API key or an OAuth sign-in.

Can an agent call Convoy and Upstash QStash without installing anything?

No hosted endpoint is listed for Convoy. Upstash QStash has a hosted endpoint at https://qstash.upstash.io/v2.

Other comparisons with Convoy or Upstash QStash

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.