Head to head · Events webhooks send · October 2026 research run
Hook0 vs Upstash QStash
Upstash QStash scores 72.3 (BB) on agent readiness against Hook0's 64.6 (B), and leads in 2 of 7 scored categories. Hook0 leads on maintenance & community. Both do events webhooks send.
Which one, for what
Hook0 B
Good for A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code.
Ahead on
- Maintenance & community, 87 against 77
Also in its favour
- Runs on your own machine
Watch for
Six advisories were published between 6 August and 9 September 2026, including a High-rated SSRF in the delivery worker fixed on 11 August
Good for Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.
Ahead on
- Reliability, 83 against 70
- Agent ergonomics, 83 against 65
Also in its favour
- Agent-ready, a grade of BB or better
- A hosted endpoint, with nothing to install
- No incidents deducted, where Hook0 loses 4 points for them
Watch for
One full-access token and one read-only token per region. No per-queue or per-destination scopes were found
Score by category
| Category | Weight this run | Hook0 | Upstash QStash | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 70 | 83 | Upstash QStash +13 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 79 | 78 | Hook0 +1 |
| Agent ergonomics | 13%16.2 | 65 | 83 | Upstash QStash +18 |
| Security & auth | 14%17.5 | 64 | 61 | Hook0 +3 |
| Payments & pricing | 10%12.5 | 40 | 40 | even |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 87 | 77 | Hook0 +10 |
| Transparency & trust | 7%8.8 | 84 | 81 | Hook0 +3 |
| Negative events | ≤15 | -4 | 0 | |
| Total | 64.6 · B | 72.3 · BB |
Facts side by side
| Fact | Hook0 | Upstash QStash |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | FGRibreau SARL | Upstash |
| Hosted endpoint | no (local only) | https://qstash.upstash.io/v2 |
| Transports | HTTP, stdio | HTTP, Streamable HTTP |
| Auth | API key | OAuth or key |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | SSPL-1.0 for the server (source available, not an OSI licence). The SDKs and the hook0-mcp server are MIT per crates.io and npm. Hook0 Cloud is a hosted service under Hook0's terms of service | Proprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT |
| Tools exposed | 23 | 10 |
| Read-only variant documented | yes | yes |
| llms.txt | yes | yes |
| MCP registry | not listed | io.github.upstash/mcp-server |
| Last release | 2026-09-21 | 2026-09-29 |
| Terms last updated | 2026-06-27 | |
| Privacy policy last updated | 2026-09-09 | |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | yes | |
| Terms restrict benchmarking | not found in the text | |
| Terms or service can change without notice | yes | |
| Arbitration or class-action waiver | not found in the text | |
| Popularity | 1.5k stars, 507 npm/wk, 11 PyPI/wk | 269 stars, 816k npm/wk, 91k PyPI/wk |
Verdicts
Hook0
Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise.
Upstash QStash
A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed.
Before you call either
Hook0
- Use a service token narrowed to one application and an expiry. A root service token covers the whole organisation, and an application secret can delete its application
- Send your own UUID as
event_idonPOST /api/v1/event/. A repeat returnsEventAlreadyIngested(409), which means the first call succeeded - Create the event type before sending. Unknown types fail with
EventTypeDoesNotExist, andlabels,occurred_atandpayload_content_typeare required - Send
payloadas a string, with JSON serialised inside it, up to 512 KiB - Set
HOOK0_API_URLforhook0-mcpto the origin without/api/v1, and setHOOK0_READ_ONLY=trueto hide the ten write tools
Upstash QStash
- Use the regional host that matches the token.
qstash.upstash.iois the EU region, and US tokens work only onqstash-us-east-1.upstash.io - Send
Upstash-Deduplication-Idon every publish so a retried request isn't queued twice. The window is 10 minutes - Budget for retries. Per the pricing FAQ each delivery attempt is billed as a message, so set
Upstash-Retriesdeliberately - Give monitoring agents the read-only token, and set
Upstash-Redact-Fieldson publish, because that token still reads message bodies and headers - Make the destination idempotent on
Upstash-Message-Id. Delivery is at least once, and duplicates can follow a server restart
Questions
Which is better for AI agents, Hook0 or Upstash QStash?
Upstash QStash scores 72.3 (BB) on agent readiness against Hook0's 64.6 (B), and leads in 2 of 7 scored categories. Hook0 leads on maintenance & community.
Do Hook0 and Upstash QStash need an API key?
Hook0 needs an API key. Upstash QStash takes an API key or an OAuth sign-in.
Can an agent call Hook0 and Upstash QStash without installing anything?
Hook0 runs on your own machine, with no hosted endpoint listed. Upstash QStash has a hosted endpoint at https://qstash.upstash.io/v2.
Other comparisons with Hook0 or Upstash QStash
Machine-readable
- This page as Markdown
/compare/hook0-vs-upstash-qstash.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/hook0.json·/api/v1/tools/upstash-qstash.json - From a terminal
anchor compare hook0 upstash-qstash(the CLI) - Over MCP
compare_tools {"a": "hook0", "b": "upstash-qstash"}at/mcp, no key