{
  "data": {
    "a": {
      "slug": "hook0",
      "name": "Hook0",
      "vendor": "FGRibreau SARL",
      "vendorUrl": "https://www.hook0.com",
      "kind": "http-api",
      "category": "webhooks",
      "summary": "Hook0 is a webhook sending service from FGRibreau SARL in France. An application posts events to a REST API and Hook0 signs, retries and logs deliveries to subscriber endpoints. It runs as an EU-hosted cloud or self-hosted under SSPL-1.0.",
      "url": "https://www.anchorterminal.com/tools/hook0",
      "markdownUrl": "https://www.anchorterminal.com/tools/hook0.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hook0.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hook0.json",
      "repo": "https://github.com/hook0/hook0",
      "license": "SSPL-1.0 for the server (source available, not an OSI licence). The SDKs and the `hook0-mcp` server are MIT per crates.io and npm. Hook0 Cloud is a hosted service under Hook0's terms of service",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "hook0-client"
        },
        {
          "registry": "pypi",
          "name": "hook0-client"
        },
        {
          "registry": "cargo",
          "name": "hook0-mcp"
        }
      ],
      "auth": "api-key",
      "authNotes": "Every call takes `Authorization: Bearer \u003ctoken\u003e` at https://app.hook0.com/api/v1. A person signs up in a browser, passes a Cloudflare Turnstile check and verifies an email address, then creates a service token in the dashboard. Service tokens are Biscuit tokens scoped to one organisation, and the holder can narrow one offline to a single application, an expiry date or an allowlist of actions. Each application also has secrets that work as Bearer tokens with full control of that application. No OAuth for API clients.",
      "pricing": "freemium",
      "pricingNotes": "Free Developer plan with no card, 100 events a day, one application and 7 days of retention, and a 429 once the quota is used. Startup is €59 a month for 30,000 events a day, then €0.003 an event. Pro is €190 a month for 100,000 events a day, then €0.0001 an event. Prices exclude VAT and are published in euros only. Subscriptions and retries aren't counted. Self-hosting is free, and a managed on-premise instance is €500 a month plus €1,000 setup (checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the documentation index, the OpenAPI document, the repository or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 23,
      "popularity": {
        "githubStars": 1494,
        "npmWeekly": 507,
        "pypiWeekly": 11,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://documentation.hook0.com/",
      "llmsTxt": "https://documentation.hook0.com/llms.txt",
      "openapi": "https://app.hook0.com/api/v1/swagger.json",
      "capabilities": [
        "events.webhooks-send"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "source-available",
        "webhooks",
        "api-key",
        "openapi",
        "llms-txt",
        "mcp",
        "free-tier",
        "no-card",
        "status-page",
        "eu-hosted",
        "typescript",
        "python",
        "rust",
        "go"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.6,
        "grade": "B",
        "agentReady": false,
        "rank": 313,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 40,
          "reliability": 70,
          "schema": 79,
          "security": 64,
          "transparency": 84
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-08-11. Server-side request forgery in the delivery worker, rated High by the vendor. An IPv6 transition address passed the filter on forbidden targets, so a tenant could make the worker reach internal addresses. Fixed in commit 3b27e932 and published with the reporter credited, so the deduction is reduced to 3 (https://documentation.hook0.com/resources/security-advisories).",
          "2026-08-24. A password reset link stayed usable after it had reset a password, rated Medium, which allowed account takeover by anyone holding a spent link. Fixed in commit 80fae0de and published, so the deduction is 1 (https://documentation.hook0.com/resources/security-advisories)."
        ],
        "verdict": "Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise.",
        "bestFor": "A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code.",
        "strengths": [
          "Public OpenAPI 3.0 document at `/api/v1/swagger.json` with 56 operations, each with a summary, a description and ten error statuses",
          "Service tokens are Biscuit tokens that the holder can narrow offline to one application, an expiry date or a read-only action list",
          "Errors follow RFC 7807 with a stable `id`, and the reference lists 46 codes generated from the API's own `/errors` endpoint",
          "Free Developer plan of 100 events a day with no card, and per-event overage prices published for both paid plans",
          "Retention by plan, sub-processors with countries, a DPA, a GDPR Article 30 register and a transfer impact assessment are all public"
        ],
        "weaknesses": [
          "Six advisories were published between 6 August and 9 September 2026, including a High-rated SSRF in the delivery worker fixed on 11 August",
          "The status page records API and delivery downtime on 27 August and 22 September 2026, both traced to the hosting provider",
          "The terms give no uptime, latency or support commitment by default. Service levels exist only in a signed Enterprise agreement",
          "Cloud registration requires a Cloudflare Turnstile token and email verification, so an agent can't create an account alone",
          "The API introduction page documents an error shape and `limit` and `offset` pagination that the OpenAPI document doesn't contain"
        ],
        "agentNotes": [
          "Use a service token narrowed to one application and an expiry. A root service token covers the whole organisation, and an application secret can delete its application",
          "Send your own UUID as `event_id` on `POST /api/v1/event/`. A repeat returns `EventAlreadyIngested` (409), which means the first call succeeded",
          "Create the event type before sending. Unknown types fail with `EventTypeDoesNotExist`, and `labels`, `occurred_at` and `payload_content_type` are required",
          "Send `payload` as a string, with JSON serialised inside it, up to 512 KiB",
          "Set `HOOK0_API_URL` for `hook0-mcp` to the origin without `/api/v1`, and set `HOOK0_READ_ONLY=true` to hide the ten write tools"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.6
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 40,
          "reliability": 70,
          "schema": 79,
          "security": 64,
          "transparency": 76
        },
        "provenanceScore": 91
      },
      "connect": {
        "install": "cargo install hook0-mcp",
        "http": "curl -X POST \"https://app.hook0.com/api/v1/event\" \\\n  -H \"Authorization: Bearer $HOOK0_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"application_id\": \"\u003capplication-id\u003e\", \"event_type\": \"user.account.created\", \"payload\": \"{\\\"user_id\\\": 123}\", \"payload_content_type\": \"application/json\", \"labels\": {\"environment\": \"tutorial\"}, \"occurred_at\": \"2026-10-08T12:00:00Z\"}'",
        "config": {
          "mcpServers": {
            "hook0": {
              "command": "hook0-mcp",
              "env": {
                "HOOK0_API_TOKEN": "your-service-token-here"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/events.webhooks-send",
        "tool": "https://letme.dev/hook0"
      },
      "area": "developer",
      "provenance": {
        "legalEntity": "FGRibreau SARL",
        "domain": "hook0.com",
        "domainRegistered": "2020-09-02",
        "endpointOnVendorDomain": true,
        "terms": "https://www.hook0.com/terms",
        "privacy": "https://www.hook0.com/privacy-policy",
        "statusPage": "https://status.hook0.com",
        "changelog": "https://gitlab.com/hook0/hook0/-/releases",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last updated 27 June 2026) name FGRibreau SARL, a French limited liability company registered at La Roche-sur-Yon under number 850 824 350, with its office at 3 rue de l'Aubepine, 85110 Chantonnay, France.",
          "The API answers at app.hook0.com, a hook0.com subdomain, per the OpenAPI document's server entry.",
          "www.hook0.com/.well-known/security.txt names security@hook0.com, a disclosure policy and an acknowledgments page, and expires on 6 August 2027.",
          "The privacy policy (last updated 9 September 2026) covers the Hook0 service and lists sub-processors with countries. A data processing addendum is published at www.hook0.com/data-processing-addendum.",
          "The documentation's changelog page only links to GitHub Releases. Releases are tagged per component on GitLab, where development happens, and each component keeps a CHANGELOG.md.",
          "RDAP for hook0.com gives a registration date of 2020-09-02."
        ],
        "score": 91
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hook0.json",
      "live": {
        "slug": "hook0",
        "vendorStatus": {
          "page": "https://status.hook0.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:03.331943028Z"
        },
        "updatedAt": "2026-10-09T07:58:03.331943028Z"
      }
    },
    "answer": "Upstash QStash scores 72.3 (BB) on agent readiness against Hook0's 64.6 (B), and leads in 2 of 7 scored categories. Hook0 leads on maintenance \u0026 community.",
    "b": {
      "slug": "upstash-qstash",
      "name": "Upstash QStash",
      "vendor": "Upstash",
      "vendorUrl": "https://upstash.com/qstash",
      "kind": "http-api",
      "category": "webhooks",
      "summary": "Upstash QStash is a hosted HTTP message queue and scheduler. A caller publishes a request to its REST API, and QStash sends it to a public URL with retries, delays, cron schedules, FIFO queues and signed requests.",
      "url": "https://www.anchorterminal.com/tools/upstash-qstash",
      "markdownUrl": "https://www.anchorterminal.com/tools/upstash-qstash.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/upstash-qstash.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/upstash-qstash.json",
      "repo": "https://github.com/upstash/qstash-js",
      "license": "Proprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://qstash.upstash.io/v2",
      "packages": [
        {
          "registry": "npm",
          "name": "@upstash/qstash"
        },
        {
          "registry": "pypi",
          "name": "qstash"
        },
        {
          "registry": "npm",
          "name": "@upstash/mcp-server"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A person signs up at console.upstash.com and copies `QSTASH_TOKEN` for a region, sent as a Bearer token or, as a documented option, in a `qstash_token` query parameter. Each region has one full-access token and one read-only token, and resetting the token revokes the old one. The hosted MCP server uses OAuth with a per-client, revocable grant that can be read-only, or account email plus a Developer API key, which can be read-only and can expire.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with 1,000 messages a day and no card. Pay as you go is $1 per 100,000 messages with 50 GB of bandwidth a month free, then $0.05 per GB. Fixed plans are $180 a month for 1M messages a day and $420 for 10M. Enterprise by quote. The pricing FAQ bills each delivery attempt, retries included, while the Markdown version of the page also says retries are free. The price of the Prod Pack add-on wasn't found (https://upstash.com/pricing/qstash).",
      "priceSummary": "$0.05 / GB",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the QStash docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 10,
      "popularity": {
        "githubStars": 269,
        "npmWeekly": 816190,
        "pypiWeekly": 90589,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://upstash.com/docs/qstash/overall/getstarted",
      "llmsTxt": "https://upstash.com/docs/llms.txt",
      "openapi": "https://upstash.com/docs/qstash/openapi.yaml",
      "registryName": "io.github.upstash/mcp-server",
      "capabilities": [
        "events.queue",
        "events.schedule",
        "events.webhooks-send",
        "events.webhooks-receive"
      ],
      "tags": [
        "hosted",
        "freemium",
        "no-card",
        "free-tier",
        "openapi",
        "mcp",
        "llms-txt",
        "closed-source",
        "typescript",
        "python",
        "status-page"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 72.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 105,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 77,
          "payments": 40,
          "reliability": 83,
          "schema": 78,
          "security": 61,
          "transparency": 81
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed.",
        "bestFor": "Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.",
        "strengths": [
          "Public OpenAPI 3.1 file with 43 operations for messages, queues, schedules, URL groups, the dead letter queue, logs and signing keys",
          "Retries default to 3 with exponential backoff capped at one day, and a destination's `Retry-After` header is honoured",
          "`Upstash-Deduplication-Id` makes a repeated publish safe for 10 minutes, with 202 returned for a duplicate",
          "Every request to the destination carries an HS256 JWT in `Upstash-Signature`, with two signing keys so rotation needs no downtime",
          "Free plan of 1,000 messages a day with no card, then $1 per 100,000 messages"
        ],
        "weaknesses": [
          "One full-access token and one read-only token per region. No per-queue or per-destination scopes were found",
          "The token is accepted as a `qstash_token` query parameter, which the webhook receiver guide relies on",
          "The Markdown pricing page says retries are free and, in its FAQ, that each retry is billed as a message",
          "Two QStash incidents in us-east-1 in 90 days, on 16 July and 28 August 2026, both under 15 minutes",
          "The docs changelog stops at February 2026, and the Python SDK last shipped on 18 March 2026"
        ],
        "agentNotes": [
          "Use the regional host that matches the token. `qstash.upstash.io` is the EU region, and US tokens work only on `qstash-us-east-1.upstash.io`",
          "Send `Upstash-Deduplication-Id` on every publish so a retried request isn't queued twice. The window is 10 minutes",
          "Budget for retries. Per the pricing FAQ each delivery attempt is billed as a message, so set `Upstash-Retries` deliberately",
          "Give monitoring agents the read-only token, and set `Upstash-Redact-Fields` on publish, because that token still reads message bodies and headers",
          "Make the destination idempotent on `Upstash-Message-Id`. Delivery is at least once, and duplicates can follow a server restart"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 72.3
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 77,
          "payments": 40,
          "reliability": 83,
          "schema": 78,
          "security": 61,
          "transparency": 62
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "npm install @upstash/qstash",
        "http": "curl -XPOST \\\n    -H 'Authorization: Bearer \u003cQSTASH_TOKEN\u003e' \\\n    -H \"Content-type: application/json\" \\\n    -d '{ \"hello\": \"world\" }' \\\n    'https://qstash.upstash.io/v2/publish/https://\u003cyour-api-url\u003e'",
        "claudeCode": "claude mcp add --scope user --transport http upstash https://mcp.upstash.com/mcp",
        "config": {
          "mcpServers": {
            "upstash": {
              "url": "https://mcp.upstash.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/events.queue",
        "tool": "https://letme.dev/upstash-qstash"
      },
      "sameCompany": [
        "upstash-vector"
      ],
      "area": "developer",
      "unitPrices": [
        {
          "item": "Pay as you go message",
          "unit": "message",
          "usd": 0.00001,
          "note": "$1 per 100,000 messages. The pricing FAQ counts each delivery attempt as a message"
        },
        {
          "item": "Bandwidth over 50 GB a month",
          "unit": "gb",
          "usd": 0.05,
          "note": "pay as you go"
        },
        {
          "item": "Fixed 1M plan",
          "unit": "month",
          "usd": 180,
          "note": "1M messages a day, 1 TB bandwidth, 50 MB messages"
        },
        {
          "item": "Fixed 10M plan",
          "unit": "month",
          "usd": 420,
          "note": "10M messages a day, 5 TB bandwidth, 50 MB messages"
        }
      ],
      "provenance": {
        "legalEntity": "Upstash, Inc.",
        "domain": "upstash.com",
        "domainRegistered": "2015-06-23",
        "endpointOnVendorDomain": true,
        "terms": "https://upstash.com/trust/terms.pdf",
        "privacy": "https://upstash.com/trust/privacy.pdf",
        "statusPage": "https://status.upstash.com",
        "changelog": "https://upstash.com/docs/qstash/overall/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last updated April 2025) name Upstash, Inc., a Delaware corporation, and list upstash.io subdomains as Upstash-owned. The QStash API answers at qstash.upstash.io and qstash-us-east-1.upstash.io.",
          "upstash.com/.well-known/security.txt names security@upstash.com, expires on 29 September 2027 and links a vulnerability disclosure policy last updated in September 2026.",
          "RDAP for upstash.com gives a registration date of 2015-06-23.",
          "The docs changelog says changes moved to GitHub Discussions from October 2025. Its own last entry is February 2026."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/upstash-qstash.json",
      "live": {
        "slug": "upstash-qstash",
        "probe": {
          "target": "https://qstash.upstash.io/v2",
          "method": "get",
          "lastAt": "2026-10-09T11:46:44.449581995Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 67,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 66,
          "p95ms24h": 90,
          "samples24h": 218,
          "samples30d": 218,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 93,
              "ok": 93
            },
            {
              "date": "2026-10-09",
              "probes": 125,
              "ok": 125
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.upstash.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T11:41:09.247014128Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "upstash/qstash-js",
            "version": "v2.12.0",
            "released": "2026-09-29",
            "seenAt": "2026-10-08T16:33:40.216498999Z"
          },
          {
            "registry": "npm",
            "name": "@upstash/mcp-server",
            "version": "0.3.0",
            "seenAt": "2026-10-08T16:33:39.314600599Z"
          },
          {
            "registry": "npm",
            "name": "@upstash/qstash",
            "version": "2.12.0",
            "seenAt": "2026-10-08T16:33:37.994139139Z"
          },
          {
            "registry": "pypi",
            "name": "qstash",
            "version": "3.4.0",
            "released": "2026-03-18",
            "seenAt": "2026-10-08T16:33:39.127706289Z"
          }
        ],
        "githubStars": 269,
        "npmWeekly": 816190,
        "pypiWeekly": 90589,
        "securityTxt": {
          "url": "https://upstash.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-09-29T00:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:47.944083119Z"
        },
        "pages": [
          {
            "url": "https://upstash.com/docs/qstash/overall/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:29.475607972Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1a6fc37bf667"
          },
          {
            "url": "https://upstash.com/pricing/qstash",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:33.644391752Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "75104b63b2e9"
          }
        ],
        "updatedAt": "2026-10-09T11:46:44.449581995Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "FGRibreau SARL",
        "b": "Upstash",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://qstash.upstash.io/v2",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "SSPL-1.0 for the server (source available, not an OSI licence). The SDKs and the `hook0-mcp` server are MIT per crates.io and npm. Hook0 Cloud is a hosted service under Hook0's terms of service",
        "b": "Proprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT",
        "name": "Licence"
      },
      {
        "a": "23",
        "b": "10",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "io.github.upstash/mcp-server",
        "name": "MCP registry"
      },
      {
        "a": "2026-09-21",
        "b": "2026-09-29",
        "name": "Last release"
      },
      {
        "a": "2026-06-27",
        "b": "",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-09",
        "b": "",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1.5k stars, 507 npm/wk, 11 PyPI/wk",
        "b": "269 stars, 816k npm/wk, 91k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Upstash QStash scores 72.3 (BB) on agent readiness against Hook0's 64.6 (B), and leads in 2 of 7 scored categories. Hook0 leads on maintenance \u0026 community.",
        "question": "Which is better for AI agents, Hook0 or Upstash QStash?"
      },
      {
        "answer": "Hook0 needs an API key. Upstash QStash takes an API key or an OAuth sign-in.",
        "question": "Do Hook0 and Upstash QStash need an API key?"
      },
      {
        "answer": "Hook0 runs on your own machine, with no hosted endpoint listed. Upstash QStash has a hosted endpoint at https://qstash.upstash.io/v2.",
        "question": "Can an agent call Hook0 and Upstash QStash without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Maintenance \u0026 community, 87 against 77"
        ],
        "also": [
          "Runs on your own machine"
        ],
        "goodFor": "A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code.",
        "slug": "hook0",
        "watchFor": "Six advisories were published between 6 August and 9 September 2026, including a High-rated SSRF in the delivery worker fixed on 11 August"
      },
      {
        "aheadOn": [
          "Reliability, 83 against 70",
          "Agent ergonomics, 83 against 65"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Hook0 loses 4 points for them"
        ],
        "goodFor": "Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.",
        "slug": "upstash-qstash",
        "watchFor": "One full-access token and one read-only token per region. No per-queue or per-destination scopes were found"
      }
    ],
    "job": {
      "capability": "events.webhooks-send",
      "name": "Events webhooks send"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/ably-vs-hook0.json",
        "title": "Ably vs Hook0",
        "url": "https://www.anchorterminal.com/compare/ably-vs-hook0"
      },
      {
        "json": "https://www.anchorterminal.com/compare/convoy-vs-hook0.json",
        "title": "Convoy vs Hook0",
        "url": "https://www.anchorterminal.com/compare/convoy-vs-hook0"
      },
      {
        "json": "https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash.json",
        "title": "Convoy vs Upstash QStash",
        "url": "https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hook0-vs-hookdeck.json",
        "title": "Hook0 vs Hookdeck",
        "url": "https://www.anchorterminal.com/compare/hook0-vs-hookdeck"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hook0-vs-pusher-channels.json",
        "title": "Hook0 vs Pusher Channels",
        "url": "https://www.anchorterminal.com/compare/hook0-vs-pusher-channels"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hook0-vs-svix.json",
        "title": "Hook0 vs Svix",
        "url": "https://www.anchorterminal.com/compare/hook0-vs-svix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pusher-channels-vs-upstash-qstash.json",
        "title": "Pusher Channels vs Upstash QStash",
        "url": "https://www.anchorterminal.com/compare/pusher-channels-vs-upstash-qstash"
      },
      {
        "json": "https://www.anchorterminal.com/compare/svix-vs-upstash-qstash.json",
        "title": "Svix vs Upstash QStash",
        "url": "https://www.anchorterminal.com/compare/svix-vs-upstash-qstash"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hookdeck-vs-upstash-qstash.json",
        "title": "Hookdeck vs Upstash QStash",
        "url": "https://www.anchorterminal.com/compare/hookdeck-vs-upstash-qstash"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ably-vs-upstash-qstash.json",
        "title": "Ably vs Upstash QStash",
        "url": "https://www.anchorterminal.com/compare/ably-vs-upstash-qstash"
      }
    ],
    "scores": [
      {
        "by": 13,
        "edge": "upstash-qstash",
        "hook0": 70,
        "key": "reliability",
        "name": "Reliability",
        "upstash-qstash": 83,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "edge": "hook0",
        "hook0": 79,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "upstash-qstash": 78,
        "weight": 13
      },
      {
        "by": 18,
        "edge": "upstash-qstash",
        "hook0": 65,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "upstash-qstash": 83,
        "weight": 13
      },
      {
        "by": 3,
        "edge": "hook0",
        "hook0": 64,
        "key": "security",
        "name": "Security \u0026 auth",
        "upstash-qstash": 61,
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "hook0": 40,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "upstash-qstash": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 10,
        "edge": "hook0",
        "hook0": 87,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "upstash-qstash": 77,
        "weight": 7
      },
      {
        "by": 3,
        "edge": "hook0",
        "hook0": 84,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "upstash-qstash": 81,
        "weight": 7
      }
    ],
    "summary": "Upstash QStash scores 72.3 (BB) on agent readiness against Hook0's 64.6 (B), and leads in 2 of 7 scored categories. Hook0 leads on maintenance \u0026 community. Both do events webhooks send.",
    "verdicts": {
      "hook0": "Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise.",
      "upstash-qstash": "A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/hook0-vs-upstash-qstash",
    "json": "https://www.anchorterminal.com/compare/hook0-vs-upstash-qstash.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/hook0-vs-upstash-qstash.md",
    "slim": "https://www.anchorterminal.com/compare/hook0-vs-upstash-qstash.min.md"
  },
  "markdown": "Upstash QStash scores 72.3 (BB) on agent readiness against Hook0's 64.6 (B), and leads in 2 of 7 scored categories. Hook0 leads on maintenance \u0026 community. Both do events webhooks send.\n\n- Hook0: grade B, 64.6/100, rank #313 of 842. Markdown https://www.anchorterminal.com/tools/hook0.md · JSON https://www.anchorterminal.com/api/v1/tools/hook0.json\n- Upstash QStash: grade BB, 72.3/100, rank #105 of 842. Markdown https://www.anchorterminal.com/tools/upstash-qstash.md · JSON https://www.anchorterminal.com/api/v1/tools/upstash-qstash.json\n\n## Which one, for what\n\n### Hook0 (B)\n\nGood for: A product that has to send signed webhooks to its own customers' endpoints with retries, replay and a delivery log, and that wants EU hosting or the option to self-host the same code.\n\nAhead on:\n- Maintenance \u0026 community, 87 against 77\n\nAlso in its favour:\n- Runs on your own machine\n\nWatch for: Six advisories were published between 6 August and 9 September 2026, including a High-rated SSRF in the delivery worker fixed on 11 August\n\n### Upstash QStash (BB)\n\nGood for: Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.\n\nAhead on:\n- Reliability, 83 against 70\n- Agent ergonomics, 83 against 65\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Hook0 loses 4 points for them\n\nWatch for: One full-access token and one read-only token per region. No per-queue or per-destination scopes were found\n\n\n## Score by category\n\n| Category | Weight | Hook0 | Upstash QStash | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 70 | 83 | Upstash QStash +13 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 79 | 78 | Hook0 +1 |\n| Agent ergonomics | 13% (16.2 this run) | 65 | 83 | Upstash QStash +18 |\n| Security \u0026 auth | 14% (17.5 this run) | 64 | 61 | Hook0 +3 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 40 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 87 | 77 | Hook0 +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 84 | 81 | Hook0 +3 |\n| Negative events | ≤15 | -4 | 0 | |\n| **Total** | | **64.6 · B** | **72.3 · BB** | |\n\n## Facts side by side\n\n| Fact | Hook0 | Upstash QStash |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | FGRibreau SARL | Upstash |\n| Hosted endpoint | no (local only) | `https://qstash.upstash.io/v2` |\n| Transports | HTTP, stdio | HTTP, Streamable HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | SSPL-1.0 for the server (source available, not an OSI licence). The SDKs and the `hook0-mcp` server are MIT per crates.io and npm. Hook0 Cloud is a hosted service under Hook0's terms of service | Proprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT |\n| Tools exposed | 23 | 10 |\n| Read-only variant documented | yes | yes |\n| llms.txt | yes | yes |\n| MCP registry | not listed | `io.github.upstash/mcp-server` |\n| Last release | 2026-09-21 | 2026-09-29 |\n| Terms last updated | 2026-06-27 |  |\n| Privacy policy last updated | 2026-09-09 |  |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | yes |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 1.5k stars, 507 npm/wk, 11 PyPI/wk | 269 stars, 816k npm/wk, 91k PyPI/wk |\n\n## Verdicts\n\n**Hook0.** Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise.\n\n**Upstash QStash.** A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed.\n\n## Before you call either\n\n### Hook0\n\n1. Use a service token narrowed to one application and an expiry. A root service token covers the whole organisation, and an application secret can delete its application\n2. Send your own UUID as `event_id` on `POST /api/v1/event/`. A repeat returns `EventAlreadyIngested` (409), which means the first call succeeded\n3. Create the event type before sending. Unknown types fail with `EventTypeDoesNotExist`, and `labels`, `occurred_at` and `payload_content_type` are required\n4. Send `payload` as a string, with JSON serialised inside it, up to 512 KiB\n5. Set `HOOK0_API_URL` for `hook0-mcp` to the origin without `/api/v1`, and set `HOOK0_READ_ONLY=true` to hide the ten write tools\n\n### Upstash QStash\n\n1. Use the regional host that matches the token. `qstash.upstash.io` is the EU region, and US tokens work only on `qstash-us-east-1.upstash.io`\n2. Send `Upstash-Deduplication-Id` on every publish so a retried request isn't queued twice. The window is 10 minutes\n3. Budget for retries. Per the pricing FAQ each delivery attempt is billed as a message, so set `Upstash-Retries` deliberately\n4. Give monitoring agents the read-only token, and set `Upstash-Redact-Fields` on publish, because that token still reads message bodies and headers\n5. Make the destination idempotent on `Upstash-Message-Id`. Delivery is at least once, and duplicates can follow a server restart\n\n## Questions\n\n### Which is better for AI agents, Hook0 or Upstash QStash?\n\nUpstash QStash scores 72.3 (BB) on agent readiness against Hook0's 64.6 (B), and leads in 2 of 7 scored categories. Hook0 leads on maintenance \u0026 community.\n\n### Do Hook0 and Upstash QStash need an API key?\n\nHook0 needs an API key. Upstash QStash takes an API key or an OAuth sign-in.\n\n### Can an agent call Hook0 and Upstash QStash without installing anything?\n\nHook0 runs on your own machine, with no hosted endpoint listed. Upstash QStash has a hosted endpoint at https://qstash.upstash.io/v2.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/hook0-vs-upstash-qstash.json, and with the fewest tokens: https://www.anchorterminal.com/compare/hook0-vs-upstash-qstash.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"hook0\", \"b\": \"upstash-qstash\"}`. From a terminal: `anchor compare hook0 upstash-qstash`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/hook0.json and https://www.anchorterminal.com/api/v1/tools/upstash-qstash.json\n\n## Other comparisons with Hook0 or Upstash QStash\n\n- [Ably vs Hook0](https://www.anchorterminal.com/compare/ably-vs-hook0.md)\n- [Convoy vs Hook0](https://www.anchorterminal.com/compare/convoy-vs-hook0.md)\n- [Convoy vs Upstash QStash](https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash.md)\n- [Hook0 vs Hookdeck](https://www.anchorterminal.com/compare/hook0-vs-hookdeck.md)\n- [Hook0 vs Pusher Channels](https://www.anchorterminal.com/compare/hook0-vs-pusher-channels.md)\n- [Hook0 vs Svix](https://www.anchorterminal.com/compare/hook0-vs-svix.md)\n- [Pusher Channels vs Upstash QStash](https://www.anchorterminal.com/compare/pusher-channels-vs-upstash-qstash.md)\n- [Svix vs Upstash QStash](https://www.anchorterminal.com/compare/svix-vs-upstash-qstash.md)\n- [Hookdeck vs Upstash QStash](https://www.anchorterminal.com/compare/hookdeck-vs-upstash-qstash.md)\n- [Ably vs Upstash QStash](https://www.anchorterminal.com/compare/ably-vs-upstash-qstash.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Hook0 vs Upstash QStash",
        "url": ""
      }
    ],
    "description": "Upstash QStash scores 72.3 (BB) on agent readiness against Hook0's 64.6 (B), and leads in 2 of 7 scored categories. Hook0 leads on maintenance \u0026 community. Both do events webhooks send. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Hook0 B 64.6",
      "Upstash QStash BB 72.3",
      "scores"
    ],
    "h1": "Hook0 vs Upstash QStash",
    "image": "https://www.anchorterminal.com/assets/og/compare-hook0-vs-upstash-qstash.png",
    "path": "/compare/hook0-vs-upstash-qstash",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Hook0 vs Upstash QStash for AI agents, B 64.6 vs BB 72.3",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/hook0-vs-upstash-qstash"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 780
  },
  "version": 1
}
