{
  "data": {
    "a": {
      "slug": "convoy",
      "name": "Convoy",
      "vendor": "Frain Technologies Inc.",
      "vendorUrl": "https://www.getconvoy.io",
      "kind": "http-api",
      "category": "webhooks",
      "summary": "Convoy is a webhooks gateway from Frain Technologies. It sends outgoing webhooks with retries and signatures and receives incoming ones, through an HTTP API on Convoy Cloud or a self-hosted, source-available server.",
      "url": "https://www.anchorterminal.com/tools/convoy",
      "markdownUrl": "https://www.anchorterminal.com/tools/convoy.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/convoy.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/convoy.json",
      "repo": "https://github.com/frain-dev/convoy",
      "license": "Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "convoy.js"
        },
        {
          "registry": "pypi",
          "name": "convoy-python"
        },
        {
          "registry": "go",
          "name": "github.com/frain-dev/convoy-go/v2"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve API keys sent as a Bearer token. A project API key is scoped to one project and is returned once when the project is created, or regenerated in project settings. A personal API key, created in the dashboard's security settings, follows its user's organisation membership and creates projects. No OAuth for API clients and no partner or sales approval. On self-hosted instances `convoy bootstrap --with-api-key` prints a personal key.",
      "pricing": "paid",
      "pricingNotes": "Convoy Cloud has a 14-day trial without a card (one project, one user, 100 events a day), then Pro at $99 a month for 25 events a second or Premium at $499 a month. Plans are flat with a throughput limit and no per-message charge. The self-hosted Community edition is free with one user and two projects, and self-hosted Premium is $999 a month (https://www.getconvoy.io/pricing, checked 2026-10-08).",
      "priceSummary": "$99 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 2877,
        "npmWeekly": 2257,
        "pypiWeekly": 679,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.getconvoy.io/docs",
      "llmsTxt": "https://www.getconvoy.io/docs/llms.txt",
      "openapi": "https://raw.githubusercontent.com/frain-dev/convoy/main/docs/v3/openapi3.json",
      "capabilities": [
        "events.webhooks-send",
        "events.webhooks-receive"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "source-available",
        "webhooks",
        "api-key",
        "openapi",
        "llms-txt",
        "no-card",
        "status-page",
        "go",
        "python",
        "typescript",
        "ruby"
      ],
      "lastRelease": "2026-09-27",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.2,
        "grade": "B",
        "agentReady": false,
        "rank": 308,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 80,
          "payments": 30,
          "reliability": 92,
          "schema": 78,
          "security": 53,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -6,
        "negativeNotes": [
          "2026-07-24. Advisory GHSA-p5vg-v7mj-f6q4, rated High. Before v26.6.8 any caller authorised on one project could read another project's source record by id, including message broker credentials in plaintext. Patched in 26.6.8 and published by the maintainers, so the deduction is reduced to 4 (https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4).",
          "2026-08-04. Until v26.7.0 the events list returned `metadata` on dynamic events, which carried the endpoint secret and custom auth headers in plaintext. The field was removed across every API version and the change is documented, so the deduction is 2 (https://www.getconvoy.io/docs/api-reference/versioning)."
        ],
        "verdict": "Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.",
        "bestFor": "A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.",
        "strengths": [
          "Public OpenAPI 3.0 spec with 68 operations, plus llms.txt and Markdown copies of every documentation page",
          "Event creation accepts an `idempotency_key`, and the API has single and batch replay and retry endpoints for events and deliveries",
          "Dated API versions (current default 2025-11-24) pinned per request with the `X-Convoy-Version` header",
          "22 tagged releases between 27 June and 27 September 2026, with breaking changes listed per release in CHANGELOG.md",
          "Convoy Cloud's upgrade policy promises at least 180 days' notice of major upgrades and deprecations"
        ],
        "weaknesses": [
          "Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8",
          "Until v26.7.0 (4 August 2026) the events list returned endpoint secrets and custom auth headers in plaintext for dynamic events",
          "No security.txt and no SECURITY.md. The trust centre at trust.getconvoy.io renders only with JavaScript, so we couldn't read it",
          "The errors page documents four HTTP codes and one sample body. 429 and Retry-After aren't in the API reference",
          "Cloud needs a browser signup, and the 14-day trial allows 100 events a day, one project and one user"
        ],
        "agentNotes": [
          "Use the regional base URL, https://us.getconvoy.cloud/api/v1 or https://eu.getconvoy.cloud/api/v1. A project key works only under /projects/{projectID}/",
          "Create an endpoint, then a subscription, then the event. An event sent to an endpoint with no subscription isn't dispatched",
          "Send `idempotency_key` on every event. A repeated key creates the event but no delivery, and the key stays reserved until retention deletes the event",
          "Create projects with a personal API key and the `orgID` query parameter. The project key in that response is shown once",
          "Before retrying an endpoint or subscription create, list endpoints by `ownerId`. Idempotency keys cover event ingestion only"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.2
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 80,
          "payments": 30,
          "reliability": 92,
          "schema": 78,
          "security": 53,
          "transparency": 65
        },
        "provenanceScore": 69
      },
      "connect": {
        "install": "curl -fsSL https://getconvoy.io/install | bash",
        "http": "curl --request POST \\\n  --url https://{region}.getconvoy.cloud/api/v1/projects/\u003cproject-id\u003e/events \\\n  --header 'Authorization: Bearer \u003capi-key\u003e' \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"endpoint_id\": \"\u003cendpoint-id\u003e\", \"event_type\": \"payment.success\", \"data\": {\"status\": \"Completed\"}}'"
      },
      "letme": {
        "capability": "https://letme.dev/events.webhooks-send",
        "tool": "https://letme.dev/convoy"
      },
      "area": "developer",
      "unitPrices": [
        {
          "item": "Cloud Pro",
          "unit": "month",
          "usd": 99,
          "note": "25 events a second, 7-day retention"
        },
        {
          "item": "Cloud Premium",
          "unit": "month",
          "usd": 499,
          "note": "custom rate limits and retention"
        },
        {
          "item": "Self-hosted Premium licence",
          "unit": "month",
          "usd": 999,
          "note": "Community edition is free"
        }
      ],
      "provenance": {
        "legalEntity": "Frain Technologies Inc.",
        "domain": "getconvoy.io",
        "domainRegistered": "2021-09-06",
        "endpointOnVendorDomain": false,
        "terms": "https://www.getconvoy.io/legal/Terms-of-Use-Convoy.pdf",
        "privacy": "https://www.getconvoy.io/legal/privacy-policy",
        "statusPage": "https://status.getconvoy.io",
        "changelog": "https://github.com/frain-dev/convoy/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The repository's LICENSE file names Frain Technologies Inc. as licensor, and the home page footer names Frain Technologies at 2261 Market Street, San Francisco, CA 94114. The terms and privacy notice say only Convoy and its affiliates, with info@frain.dev as contact.",
          "The Cloud API answers at us.getconvoy.cloud and eu.getconvoy.cloud, a different registered domain from getconvoy.io. The vendor's own docs and OpenAPI spec name both hosts.",
          "www.getconvoy.io/.well-known/security.txt returns 404. us.getconvoy.cloud returns the dashboard's HTML at that path. The GitHub repository has no SECURITY.md but accepts private vulnerability reports.",
          "The privacy notice is dated 1 June 2023. The DPA at getconvoy.io/legal/dpa points to a sub-processor list at trust.getconvoy.io/subprocessors, which renders only with JavaScript and which we couldn't read.",
          "RDAP for getconvoy.io gives a registration date of 2021-09-06."
        ],
        "score": 69
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/convoy.json",
      "live": {
        "slug": "convoy",
        "vendorStatus": {
          "page": "https://status.getconvoy.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:32.888423561Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "frain-dev/convoy",
            "version": "v26.8.0",
            "released": "2026-09-28",
            "seenAt": "2026-10-08T16:07:07.309156702Z"
          },
          {
            "registry": "npm",
            "name": "convoy.js",
            "version": "1.1.0",
            "seenAt": "2026-10-08T16:07:02.917445318Z"
          },
          {
            "registry": "pypi",
            "name": "convoy-python",
            "version": "0.2.0",
            "released": "2023-05-16",
            "seenAt": "2026-10-08T16:07:07.117567905Z"
          }
        ],
        "githubStars": 2877,
        "npmWeekly": 2257,
        "pypiWeekly": 679,
        "securityTxt": {
          "url": "https://getconvoy.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:08.354465852Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/frain-dev/convoy/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:09.887860175Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "91084795c305"
          },
          {
            "url": "https://www.getconvoy.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:58.163197054Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "63dc1731ded0"
          },
          {
            "url": "https://www.getconvoy.io/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:55.875642867Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2ffdcb5dca1d"
          }
        ],
        "updatedAt": "2026-10-08T19:06:32.888423561Z"
      }
    },
    "answer": "Upstash QStash scores 72.3 (BB) on agent readiness against Convoy's 62.2 (B), and leads in 4 of 7 scored categories. Convoy leads on reliability.",
    "b": {
      "slug": "upstash-qstash",
      "name": "Upstash QStash",
      "vendor": "Upstash",
      "vendorUrl": "https://upstash.com/qstash",
      "kind": "http-api",
      "category": "webhooks",
      "summary": "Upstash QStash is a hosted HTTP message queue and scheduler. A caller publishes a request to its REST API, and QStash sends it to a public URL with retries, delays, cron schedules, FIFO queues and signed requests.",
      "url": "https://www.anchorterminal.com/tools/upstash-qstash",
      "markdownUrl": "https://www.anchorterminal.com/tools/upstash-qstash.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/upstash-qstash.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/upstash-qstash.json",
      "repo": "https://github.com/upstash/qstash-js",
      "license": "Proprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://qstash.upstash.io/v2",
      "packages": [
        {
          "registry": "npm",
          "name": "@upstash/qstash"
        },
        {
          "registry": "pypi",
          "name": "qstash"
        },
        {
          "registry": "npm",
          "name": "@upstash/mcp-server"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A person signs up at console.upstash.com and copies `QSTASH_TOKEN` for a region, sent as a Bearer token or, as a documented option, in a `qstash_token` query parameter. Each region has one full-access token and one read-only token, and resetting the token revokes the old one. The hosted MCP server uses OAuth with a per-client, revocable grant that can be read-only, or account email plus a Developer API key, which can be read-only and can expire.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with 1,000 messages a day and no card. Pay as you go is $1 per 100,000 messages with 50 GB of bandwidth a month free, then $0.05 per GB. Fixed plans are $180 a month for 1M messages a day and $420 for 10M. Enterprise by quote. The pricing FAQ bills each delivery attempt, retries included, while the Markdown version of the page also says retries are free. The price of the Prod Pack add-on wasn't found (https://upstash.com/pricing/qstash).",
      "priceSummary": "$0.05 / GB",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the QStash docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 10,
      "popularity": {
        "githubStars": 269,
        "npmWeekly": 816190,
        "pypiWeekly": 90589,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://upstash.com/docs/qstash/overall/getstarted",
      "llmsTxt": "https://upstash.com/docs/llms.txt",
      "openapi": "https://upstash.com/docs/qstash/openapi.yaml",
      "registryName": "io.github.upstash/mcp-server",
      "capabilities": [
        "events.queue",
        "events.schedule",
        "events.webhooks-send",
        "events.webhooks-receive"
      ],
      "tags": [
        "hosted",
        "freemium",
        "no-card",
        "free-tier",
        "openapi",
        "mcp",
        "llms-txt",
        "closed-source",
        "typescript",
        "python",
        "status-page"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 72.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 90,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 77,
          "payments": 40,
          "reliability": 83,
          "schema": 78,
          "security": 61,
          "transparency": 81
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed.",
        "bestFor": "Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.",
        "strengths": [
          "Public OpenAPI 3.1 file with 43 operations for messages, queues, schedules, URL groups, the dead letter queue, logs and signing keys",
          "Retries default to 3 with exponential backoff capped at one day, and a destination's `Retry-After` header is honoured",
          "`Upstash-Deduplication-Id` makes a repeated publish safe for 10 minutes, with 202 returned for a duplicate",
          "Every request to the destination carries an HS256 JWT in `Upstash-Signature`, with two signing keys so rotation needs no downtime",
          "Free plan of 1,000 messages a day with no card, then $1 per 100,000 messages"
        ],
        "weaknesses": [
          "One full-access token and one read-only token per region. No per-queue or per-destination scopes were found",
          "The token is accepted as a `qstash_token` query parameter, which the webhook receiver guide relies on",
          "The Markdown pricing page says retries are free and, in its FAQ, that each retry is billed as a message",
          "Two QStash incidents in us-east-1 in 90 days, on 16 July and 28 August 2026, both under 15 minutes",
          "The docs changelog stops at February 2026, and the Python SDK last shipped on 18 March 2026"
        ],
        "agentNotes": [
          "Use the regional host that matches the token. `qstash.upstash.io` is the EU region, and US tokens work only on `qstash-us-east-1.upstash.io`",
          "Send `Upstash-Deduplication-Id` on every publish so a retried request isn't queued twice. The window is 10 minutes",
          "Budget for retries. Per the pricing FAQ each delivery attempt is billed as a message, so set `Upstash-Retries` deliberately",
          "Give monitoring agents the read-only token, and set `Upstash-Redact-Fields` on publish, because that token still reads message bodies and headers",
          "Make the destination idempotent on `Upstash-Message-Id`. Delivery is at least once, and duplicates can follow a server restart"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 72.3
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 77,
          "payments": 40,
          "reliability": 83,
          "schema": 78,
          "security": 61,
          "transparency": 62
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "npm install @upstash/qstash",
        "http": "curl -XPOST \\\n    -H 'Authorization: Bearer \u003cQSTASH_TOKEN\u003e' \\\n    -H \"Content-type: application/json\" \\\n    -d '{ \"hello\": \"world\" }' \\\n    'https://qstash.upstash.io/v2/publish/https://\u003cyour-api-url\u003e'",
        "claudeCode": "claude mcp add --scope user --transport http upstash https://mcp.upstash.com/mcp",
        "config": {
          "mcpServers": {
            "upstash": {
              "url": "https://mcp.upstash.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/events.queue",
        "tool": "https://letme.dev/upstash-qstash"
      },
      "sameCompany": [
        "upstash-vector"
      ],
      "area": "developer",
      "unitPrices": [
        {
          "item": "Pay as you go message",
          "unit": "message",
          "usd": 0.00001,
          "note": "$1 per 100,000 messages. The pricing FAQ counts each delivery attempt as a message"
        },
        {
          "item": "Bandwidth over 50 GB a month",
          "unit": "gb",
          "usd": 0.05,
          "note": "pay as you go"
        },
        {
          "item": "Fixed 1M plan",
          "unit": "month",
          "usd": 180,
          "note": "1M messages a day, 1 TB bandwidth, 50 MB messages"
        },
        {
          "item": "Fixed 10M plan",
          "unit": "month",
          "usd": 420,
          "note": "10M messages a day, 5 TB bandwidth, 50 MB messages"
        }
      ],
      "provenance": {
        "legalEntity": "Upstash, Inc.",
        "domain": "upstash.com",
        "domainRegistered": "2015-06-23",
        "endpointOnVendorDomain": true,
        "terms": "https://upstash.com/trust/terms.pdf",
        "privacy": "https://upstash.com/trust/privacy.pdf",
        "statusPage": "https://status.upstash.com",
        "changelog": "https://upstash.com/docs/qstash/overall/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last updated April 2025) name Upstash, Inc., a Delaware corporation, and list upstash.io subdomains as Upstash-owned. The QStash API answers at qstash.upstash.io and qstash-us-east-1.upstash.io.",
          "upstash.com/.well-known/security.txt names security@upstash.com, expires on 29 September 2027 and links a vulnerability disclosure policy last updated in September 2026.",
          "RDAP for upstash.com gives a registration date of 2015-06-23.",
          "The docs changelog says changes moved to GitHub Discussions from October 2025. Its own last entry is February 2026."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/upstash-qstash.json",
      "live": {
        "slug": "upstash-qstash",
        "probe": {
          "target": "https://qstash.upstash.io/v2",
          "method": "get",
          "lastAt": "2026-10-08T19:09:01.204709368Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 66,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 67,
          "p95ms24h": 116,
          "samples24h": 42,
          "samples30d": 42,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 42,
              "ok": 42
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.upstash.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:07:02.870400275Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "upstash/qstash-js",
            "version": "v2.12.0",
            "released": "2026-09-29",
            "seenAt": "2026-10-08T16:33:40.216498999Z"
          },
          {
            "registry": "npm",
            "name": "@upstash/mcp-server",
            "version": "0.3.0",
            "seenAt": "2026-10-08T16:33:39.314600599Z"
          },
          {
            "registry": "npm",
            "name": "@upstash/qstash",
            "version": "2.12.0",
            "seenAt": "2026-10-08T16:33:37.994139139Z"
          },
          {
            "registry": "pypi",
            "name": "qstash",
            "version": "3.4.0",
            "released": "2026-03-18",
            "seenAt": "2026-10-08T16:33:39.127706289Z"
          }
        ],
        "githubStars": 269,
        "npmWeekly": 816190,
        "pypiWeekly": 90589,
        "securityTxt": {
          "url": "https://upstash.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-09-29T00:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:47.944083119Z"
        },
        "pages": [
          {
            "url": "https://upstash.com/docs/qstash/overall/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:29.475607972Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1a6fc37bf667"
          },
          {
            "url": "https://upstash.com/pricing/qstash",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:33.644391752Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "75104b63b2e9"
          }
        ],
        "updatedAt": "2026-10-08T19:09:01.204709368Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Frain Technologies Inc.",
        "b": "Upstash",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://qstash.upstash.io/v2",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use",
        "b": "Proprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "10",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "io.github.upstash/mcp-server",
        "name": "MCP registry"
      },
      {
        "a": "2026-09-27",
        "b": "2026-09-29",
        "name": "Last release"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms last updated"
      },
      {
        "a": "2023-06-01",
        "b": "",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "2.9k stars, 2.3k npm/wk, 679 PyPI/wk",
        "b": "269 stars, 816k npm/wk, 91k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Upstash QStash scores 72.3 (BB) on agent readiness against Convoy's 62.2 (B), and leads in 4 of 7 scored categories. Convoy leads on reliability.",
        "question": "Which is better for AI agents, Convoy or Upstash QStash?"
      },
      {
        "answer": "Convoy needs an API key. Upstash QStash takes an API key or an OAuth sign-in.",
        "question": "Do Convoy and Upstash QStash need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Convoy. Upstash QStash has a hosted endpoint at https://qstash.upstash.io/v2.",
        "question": "Can an agent call Convoy and Upstash QStash without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 92 against 83"
        ],
        "also": null,
        "goodFor": "A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.",
        "slug": "convoy",
        "watchFor": "Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8"
      },
      {
        "aheadOn": [
          "Agent ergonomics, 83 against 69",
          "Security \u0026 auth, 61 against 53",
          "Payments \u0026 pricing, 40 against 30",
          "Transparency \u0026 trust, 81 against 67"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Convoy loses 6 points for them"
        ],
        "goodFor": "Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.",
        "slug": "upstash-qstash",
        "watchFor": "One full-access token and one read-only token per region. No per-queue or per-destination scopes were found"
      }
    ],
    "job": {
      "capability": "events.webhooks-send",
      "name": "Events webhooks send"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/ably-vs-convoy.json",
        "title": "Ably vs Convoy",
        "url": "https://www.anchorterminal.com/compare/ably-vs-convoy"
      },
      {
        "json": "https://www.anchorterminal.com/compare/convoy-vs-hookdeck.json",
        "title": "Convoy vs Hookdeck",
        "url": "https://www.anchorterminal.com/compare/convoy-vs-hookdeck"
      },
      {
        "json": "https://www.anchorterminal.com/compare/convoy-vs-svix.json",
        "title": "Convoy vs Svix",
        "url": "https://www.anchorterminal.com/compare/convoy-vs-svix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/svix-vs-upstash-qstash.json",
        "title": "Svix vs Upstash QStash",
        "url": "https://www.anchorterminal.com/compare/svix-vs-upstash-qstash"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hookdeck-vs-upstash-qstash.json",
        "title": "Hookdeck vs Upstash QStash",
        "url": "https://www.anchorterminal.com/compare/hookdeck-vs-upstash-qstash"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ably-vs-upstash-qstash.json",
        "title": "Ably vs Upstash QStash",
        "url": "https://www.anchorterminal.com/compare/ably-vs-upstash-qstash"
      }
    ],
    "scores": [
      {
        "by": 9,
        "convoy": 92,
        "edge": "convoy",
        "key": "reliability",
        "name": "Reliability",
        "upstash-qstash": 83,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 0,
        "convoy": 78,
        "edge": "",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "upstash-qstash": 78,
        "weight": 13
      },
      {
        "by": 14,
        "convoy": 69,
        "edge": "upstash-qstash",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "upstash-qstash": 83,
        "weight": 13
      },
      {
        "by": 8,
        "convoy": 53,
        "edge": "upstash-qstash",
        "key": "security",
        "name": "Security \u0026 auth",
        "upstash-qstash": 61,
        "weight": 14
      },
      {
        "by": 10,
        "convoy": 30,
        "edge": "upstash-qstash",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "upstash-qstash": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "convoy": 80,
        "edge": "convoy",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "upstash-qstash": 77,
        "weight": 7
      },
      {
        "by": 14,
        "convoy": 67,
        "edge": "upstash-qstash",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "upstash-qstash": 81,
        "weight": 7
      }
    ],
    "summary": "Upstash QStash scores 72.3 (BB) on agent readiness against Convoy's 62.2 (B), and leads in 4 of 7 scored categories. Convoy leads on reliability. Both do events webhooks send.",
    "verdicts": {
      "convoy": "Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.",
      "upstash-qstash": "A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash",
    "json": "https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash.md",
    "slim": "https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash.min.md"
  },
  "markdown": "Upstash QStash scores 72.3 (BB) on agent readiness against Convoy's 62.2 (B), and leads in 4 of 7 scored categories. Convoy leads on reliability. Both do events webhooks send.\n\n- Convoy: grade B, 62.2/100, rank #308 of 629. Markdown https://www.anchorterminal.com/tools/convoy.md · JSON https://www.anchorterminal.com/api/v1/tools/convoy.json\n- Upstash QStash: grade BB, 72.3/100, rank #90 of 629. Markdown https://www.anchorterminal.com/tools/upstash-qstash.md · JSON https://www.anchorterminal.com/api/v1/tools/upstash-qstash.json\n\n## Which one, for what\n\n### Convoy (B)\n\nGood for: A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.\n\nAhead on:\n- Reliability, 92 against 83\n\nWatch for: Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8\n\n### Upstash QStash (BB)\n\nGood for: Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.\n\nAhead on:\n- Agent ergonomics, 83 against 69\n- Security \u0026 auth, 61 against 53\n- Payments \u0026 pricing, 40 against 30\n- Transparency \u0026 trust, 81 against 67\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Convoy loses 6 points for them\n\nWatch for: One full-access token and one read-only token per region. No per-queue or per-destination scopes were found\n\n\n## Score by category\n\n| Category | Weight | Convoy | Upstash QStash | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 92 | 83 | Convoy +9 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 78 | 78 | even |\n| Agent ergonomics | 13% (16.2 this run) | 69 | 83 | Upstash QStash +14 |\n| Security \u0026 auth | 14% (17.5 this run) | 53 | 61 | Upstash QStash +8 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 40 | Upstash QStash +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 77 | Convoy +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 67 | 81 | Upstash QStash +14 |\n| Negative events | ≤15 | -6 | 0 | |\n| **Total** | | **62.2 · B** | **72.3 · BB** | |\n\n## Facts side by side\n\n| Fact | Convoy | Upstash QStash |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Frain Technologies Inc. | Upstash |\n| Hosted endpoint | no (local only) | `https://qstash.upstash.io/v2` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use | Proprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT |\n| Tools exposed | none | 10 |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| MCP registry | not listed | `io.github.upstash/mcp-server` |\n| Last release | 2026-09-27 | 2026-09-29 |\n| Terms last updated |  |  |\n| Privacy policy last updated | 2023-06-01 |  |\n| Customer content may train models |  |  |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 2.9k stars, 2.3k npm/wk, 679 PyPI/wk | 269 stars, 816k npm/wk, 91k PyPI/wk |\n\n## Verdicts\n\n**Convoy.** Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.\n\n**Upstash QStash.** A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed.\n\n## Before you call either\n\n### Convoy\n\n1. Use the regional base URL, https://us.getconvoy.cloud/api/v1 or https://eu.getconvoy.cloud/api/v1. A project key works only under /projects/{projectID}/\n2. Create an endpoint, then a subscription, then the event. An event sent to an endpoint with no subscription isn't dispatched\n3. Send `idempotency_key` on every event. A repeated key creates the event but no delivery, and the key stays reserved until retention deletes the event\n4. Create projects with a personal API key and the `orgID` query parameter. The project key in that response is shown once\n5. Before retrying an endpoint or subscription create, list endpoints by `ownerId`. Idempotency keys cover event ingestion only\n\n### Upstash QStash\n\n1. Use the regional host that matches the token. `qstash.upstash.io` is the EU region, and US tokens work only on `qstash-us-east-1.upstash.io`\n2. Send `Upstash-Deduplication-Id` on every publish so a retried request isn't queued twice. The window is 10 minutes\n3. Budget for retries. Per the pricing FAQ each delivery attempt is billed as a message, so set `Upstash-Retries` deliberately\n4. Give monitoring agents the read-only token, and set `Upstash-Redact-Fields` on publish, because that token still reads message bodies and headers\n5. Make the destination idempotent on `Upstash-Message-Id`. Delivery is at least once, and duplicates can follow a server restart\n\n## Questions\n\n### Which is better for AI agents, Convoy or Upstash QStash?\n\nUpstash QStash scores 72.3 (BB) on agent readiness against Convoy's 62.2 (B), and leads in 4 of 7 scored categories. Convoy leads on reliability.\n\n### Do Convoy and Upstash QStash need an API key?\n\nConvoy needs an API key. Upstash QStash takes an API key or an OAuth sign-in.\n\n### Can an agent call Convoy and Upstash QStash without installing anything?\n\nNo hosted endpoint is listed for Convoy. Upstash QStash has a hosted endpoint at https://qstash.upstash.io/v2.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash.json, and with the fewest tokens: https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"convoy\", \"b\": \"upstash-qstash\"}`. From a terminal: `anchor compare convoy upstash-qstash`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/convoy.json and https://www.anchorterminal.com/api/v1/tools/upstash-qstash.json\n\n## Other comparisons with Convoy or Upstash QStash\n\n- [Ably vs Convoy](https://www.anchorterminal.com/compare/ably-vs-convoy.md)\n- [Convoy vs Hookdeck](https://www.anchorterminal.com/compare/convoy-vs-hookdeck.md)\n- [Convoy vs Svix](https://www.anchorterminal.com/compare/convoy-vs-svix.md)\n- [Svix vs Upstash QStash](https://www.anchorterminal.com/compare/svix-vs-upstash-qstash.md)\n- [Hookdeck vs Upstash QStash](https://www.anchorterminal.com/compare/hookdeck-vs-upstash-qstash.md)\n- [Ably vs Upstash QStash](https://www.anchorterminal.com/compare/ably-vs-upstash-qstash.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Convoy vs Upstash QStash",
        "url": ""
      }
    ],
    "description": "Upstash QStash scores 72.3 (BB) on agent readiness against Convoy's 62.2 (B), and leads in 4 of 7 scored categories. Convoy leads on reliability. Both do events webhooks send. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Convoy B 62.2",
      "Upstash QStash BB 72.3",
      "scores"
    ],
    "h1": "Convoy vs Upstash QStash",
    "image": "https://www.anchorterminal.com/assets/og/compare-convoy-vs-upstash-qstash.png",
    "path": "/compare/convoy-vs-upstash-qstash",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Convoy vs Upstash QStash for AI agents, B 62.2 vs BB 72.3",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash"
  },
  "tokens": {
    "markdown": 2050,
    "slim": 680
  },
  "version": 1
}
