Head to head · Events webhooks send · October 2026 research run

Hook0 vs Upstash QStash

Upstash QStash scores 72.3 (BB) on agent readiness against Hook0's 64.6 (B), and leads in 2 of 7 scored categories. Hook0 leads on maintenance & community. Both do events webhooks send.

Which one, for what

Hook0 B

Good for A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code.

Ahead on

  • Maintenance & community, 87 against 77

Also in its favour

  • Runs on your own machine

Watch for

Six advisories were published between 6 August and 9 September 2026, including a High-rated SSRF in the delivery worker fixed on 11 August

Upstash QStash BB

Good for Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.

Ahead on

  • Reliability, 83 against 70
  • Agent ergonomics, 83 against 65

Also in its favour

  • Agent-ready, a grade of BB or better
  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Hook0 loses 4 points for them

Watch for

One full-access token and one read-only token per region. No per-queue or per-destination scopes were found

Score by category

CategoryWeight this runHook0Upstash QStashEdge
Reliability16%207083Upstash QStash +13
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27978Hook0 +1
Agent ergonomics13%16.26583Upstash QStash +18
Security & auth14%17.56461Hook0 +3
Payments & pricing10%12.54040even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88777Hook0 +10
Transparency & trust7%8.88481Hook0 +3
Negative events≤15-40
Total64.6 · B72.3 · BB

Facts side by side

FactHook0Upstash QStash
KindHTTP APIHTTP API
VendorFGRibreau SARLUpstash
Hosted endpointno (local only)https://qstash.upstash.io/v2
TransportsHTTP, stdioHTTP, Streamable HTTP
AuthAPI keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceSSPL-1.0 for the server (source available, not an OSI licence). The SDKs and the hook0-mcp server are MIT per crates.io and npm. Hook0 Cloud is a hosted service under Hook0's terms of serviceProprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT
Tools exposed2310
Read-only variant documentedyesyes
llms.txtyesyes
MCP registrynot listedio.github.upstash/mcp-server
Last release2026-09-212026-09-29
Terms last updated2026-06-27
Privacy policy last updated2026-09-09
Customer content may train modelsnot found in the text
Terms restrict automated accessyes
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticeyes
Arbitration or class-action waivernot found in the text
Popularity1.5k stars, 507 npm/wk, 11 PyPI/wk269 stars, 816k npm/wk, 91k PyPI/wk

Verdicts

Hook0

Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise.

Upstash QStash

A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed.

Before you call either

Hook0

  1. Use a service token narrowed to one application and an expiry. A root service token covers the whole organisation, and an application secret can delete its application
  2. Send your own UUID as event_id on POST /api/v1/event/. A repeat returns EventAlreadyIngested (409), which means the first call succeeded
  3. Create the event type before sending. Unknown types fail with EventTypeDoesNotExist, and labels, occurred_at and payload_content_type are required
  4. Send payload as a string, with JSON serialised inside it, up to 512 KiB
  5. Set HOOK0_API_URL for hook0-mcp to the origin without /api/v1, and set HOOK0_READ_ONLY=true to hide the ten write tools

Upstash QStash

  1. Use the regional host that matches the token. qstash.upstash.io is the EU region, and US tokens work only on qstash-us-east-1.upstash.io
  2. Send Upstash-Deduplication-Id on every publish so a retried request isn't queued twice. The window is 10 minutes
  3. Budget for retries. Per the pricing FAQ each delivery attempt is billed as a message, so set Upstash-Retries deliberately
  4. Give monitoring agents the read-only token, and set Upstash-Redact-Fields on publish, because that token still reads message bodies and headers
  5. Make the destination idempotent on Upstash-Message-Id. Delivery is at least once, and duplicates can follow a server restart

Questions

Which is better for AI agents, Hook0 or Upstash QStash?

Upstash QStash scores 72.3 (BB) on agent readiness against Hook0's 64.6 (B), and leads in 2 of 7 scored categories. Hook0 leads on maintenance & community.

Do Hook0 and Upstash QStash need an API key?

Hook0 needs an API key. Upstash QStash takes an API key or an OAuth sign-in.

Can an agent call Hook0 and Upstash QStash without installing anything?

Hook0 runs on your own machine, with no hosted endpoint listed. Upstash QStash has a hosted endpoint at https://qstash.upstash.io/v2.

Other comparisons with Hook0 or Upstash QStash

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.