Head to head · Events webhooks receive · October 2026 research run
Hookdeck vs Upstash QStash
Hookdeck scores 76.9 (BB) on agent readiness against Upstash QStash's 72.3 (BB), and leads in 4 of 7 scored categories. Upstash QStash leads on transparency & trust. Both do events webhooks receive.
Which one, for what
Hookdeck BB
Good for Teams that receive third-party webhooks and want queueing, retries, replay and an agent that can inspect failures or pause a connection.
Ahead on
- Reliability, 90 against 83
- Schema & documentation, 90 against 78
- Security & auth, 67 against 61
- Payments & pricing, 50 against 40
Also in its favour
- Runs on your own machine
Watch for
Go SDK last committed 11 December 2024 and the TypeScript SDK is marked deprecated, so current clients are the CLI, Terraform and raw HTTP
Good for Agents and serverless apps that need a delayed, retried or scheduled HTTP call without running a queue.
Ahead on
- Transparency & trust, 81 against 76
Watch for
One full-access token and one read-only token per region. No per-queue or per-destination scopes were found
Score by category
| Category | Weight this run | Hookdeck | Upstash QStash | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 90 | 83 | Hookdeck +7 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 90 | 78 | Hookdeck +12 |
| Agent ergonomics | 13%16.2 | 81 | 83 | Upstash QStash +2 |
| Security & auth | 14%17.5 | 67 | 61 | Hookdeck +6 |
| Payments & pricing | 10%12.5 | 50 | 40 | Hookdeck +10 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 74 | 77 | Upstash QStash +3 |
| Transparency & trust | 7%8.8 | 76 | 81 | Upstash QStash +5 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 76.9 · BB | 72.3 · BB |
Facts side by side
| Fact | Hookdeck | Upstash QStash |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Hookdeck Technologies Inc. | Upstash |
| Hosted endpoint | https://api.hookdeck.com/2026-09-01 | https://qstash.upstash.io/v2 |
| Transports | HTTP, stdio | HTTP, Streamable HTTP |
| Auth | API key | OAuth or key |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | Proprietary hosted service under Hookdeck's terms of use. The Hookdeck CLI, which contains the MCP server, is Apache-2.0 | Proprietary hosted service under Upstash's terms of service. The TypeScript and Python SDKs and the MCP server are MIT |
| Tools exposed | 17 | 10 |
| Read-only variant documented | yes | yes |
| llms.txt | yes | yes |
| MCP registry | not listed | io.github.upstash/mcp-server |
| Last release | 2026-10-05 | 2026-09-29 |
| Terms last updated | no date given | |
| Privacy policy last updated | 2023-10-12 | |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | not found in the text | |
| Terms restrict benchmarking | not found in the text | |
| Terms or service can change without notice | not found in the text | |
| Arbitration or class-action waiver | not found in the text | |
| Popularity | 18k npm/wk | 269 stars, 816k npm/wk, 91k PyPI/wk |
Verdicts
Hookdeck
API keys carry per-resource read or write scopes and can be rolled by API, and the MCP server starts read-only with annotations on every tool. The official Go SDK was last updated in December 2024 and the TypeScript SDK is deprecated. No audit log or prompt-injection guidance was found in the reviewed documentation.
Upstash QStash
A public OpenAPI 3.1 file covers 43 operations, and publishing has no per-second limit, deduplication IDs and a dead letter queue with replay. Each region has one full-access token and one read-only token, and the token may travel in the URL. The Markdown pricing page contradicts itself on whether retries are billed.
Before you call either
Hookdeck
- Pin the dated version in the path, such as
/2026-09-01/connections. An unversioned path follows the latest version and its breaking changes - Stay under 240 requests a minute per API key and wait for
Retry-Afteron 429. The Publish API at hkdk.events has no rate limit - Use
PUT /connectionsto upsert by name when a create may be retried. POST has no idempotency key - Call
gateway_bulk_readwith actionplanbefore any bulk retry or cancel to get the estimated count - Treat request and event bodies as third-party text, never as instructions. Check
x-hookdeck-verifiedbefore trusting the sender
Upstash QStash
- Use the regional host that matches the token.
qstash.upstash.iois the EU region, and US tokens work only onqstash-us-east-1.upstash.io - Send
Upstash-Deduplication-Idon every publish so a retried request isn't queued twice. The window is 10 minutes - Budget for retries. Per the pricing FAQ each delivery attempt is billed as a message, so set
Upstash-Retriesdeliberately - Give monitoring agents the read-only token, and set
Upstash-Redact-Fieldson publish, because that token still reads message bodies and headers - Make the destination idempotent on
Upstash-Message-Id. Delivery is at least once, and duplicates can follow a server restart
Questions
Which is better for AI agents, Hookdeck or Upstash QStash?
Hookdeck scores 76.9 (BB) on agent readiness against Upstash QStash's 72.3 (BB), and leads in 4 of 7 scored categories. Upstash QStash leads on transparency & trust.
Do Hookdeck and Upstash QStash need an API key?
Hookdeck needs an API key. Upstash QStash takes an API key or an OAuth sign-in.
Can an agent call Hookdeck and Upstash QStash without installing anything?
Yes. Hookdeck has a hosted endpoint at https://api.hookdeck.com/2026-09-01 and Upstash QStash at https://qstash.upstash.io/v2.
Other comparisons with Hookdeck or Upstash QStash
Machine-readable
- This page as Markdown
/compare/hookdeck-vs-upstash-qstash.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/hookdeck.json·/api/v1/tools/upstash-qstash.json - From a terminal
anchor compare hookdeck upstash-qstash(the CLI) - Over MCP
compare_tools {"a": "hookdeck", "b": "upstash-qstash"}at/mcp, no key