{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/hookdeck.json",
        "name": "Hookdeck",
        "score": 76.9,
        "shared": [
          "events.webhooks-receive",
          "events.webhooks-send"
        ],
        "slug": "hookdeck"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/ably.json",
        "name": "Ably",
        "score": 75,
        "shared": [
          "events.webhooks-send",
          "events.webhooks-receive"
        ],
        "slug": "ably"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/svix.json",
        "name": "Svix",
        "score": 74,
        "shared": [
          "events.webhooks-send",
          "events.webhooks-receive"
        ],
        "slug": "svix"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/upstash-qstash.json",
        "name": "Upstash QStash",
        "score": 72.3,
        "shared": [
          "events.webhooks-send",
          "events.webhooks-receive"
        ],
        "slug": "upstash-qstash"
      }
    ],
    "tool": {
      "slug": "convoy",
      "name": "Convoy",
      "vendor": "Frain Technologies Inc.",
      "vendorUrl": "https://www.getconvoy.io",
      "kind": "http-api",
      "category": "webhooks",
      "summary": "Convoy is a webhooks gateway from Frain Technologies. It sends outgoing webhooks with retries and signatures and receives incoming ones, through an HTTP API on Convoy Cloud or a self-hosted, source-available server.",
      "url": "https://www.anchorterminal.com/tools/convoy",
      "markdownUrl": "https://www.anchorterminal.com/tools/convoy.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/convoy.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/convoy.json",
      "repo": "https://github.com/frain-dev/convoy",
      "license": "Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "convoy.js"
        },
        {
          "registry": "pypi",
          "name": "convoy-python"
        },
        {
          "registry": "go",
          "name": "github.com/frain-dev/convoy-go/v2"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve API keys sent as a Bearer token. A project API key is scoped to one project and is returned once when the project is created, or regenerated in project settings. A personal API key, created in the dashboard's security settings, follows its user's organisation membership and creates projects. No OAuth for API clients and no partner or sales approval. On self-hosted instances `convoy bootstrap --with-api-key` prints a personal key.",
      "pricing": "paid",
      "pricingNotes": "Convoy Cloud has a 14-day trial without a card (one project, one user, 100 events a day), then Pro at $99 a month for 25 events a second or Premium at $499 a month. Plans are flat with a throughput limit and no per-message charge. The self-hosted Community edition is free with one user and two projects, and self-hosted Premium is $999 a month (https://www.getconvoy.io/pricing, checked 2026-10-08).",
      "priceSummary": "$99 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 2877,
        "npmWeekly": 2257,
        "pypiWeekly": 679,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.getconvoy.io/docs",
      "llmsTxt": "https://www.getconvoy.io/docs/llms.txt",
      "openapi": "https://raw.githubusercontent.com/frain-dev/convoy/main/docs/v3/openapi3.json",
      "capabilities": [
        "events.webhooks-send",
        "events.webhooks-receive"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "source-available",
        "webhooks",
        "api-key",
        "openapi",
        "llms-txt",
        "no-card",
        "status-page",
        "go",
        "python",
        "typescript",
        "ruby"
      ],
      "lastRelease": "2026-09-27",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.2,
        "grade": "B",
        "agentReady": false,
        "rank": 308,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 80,
          "payments": 30,
          "reliability": 92,
          "schema": 78,
          "security": 53,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 92,
            "points": 18.4,
            "reason": "Graded as a hosted service, Convoy Cloud. status.getconvoy.io on incident.io lists the website and the US and EU data and control planes, with data since July 2024 (20). It shows 100 per cent uptime on every component from July to October 2026 and no incidents, though the day-by-day calendar didn't load for us (30). Cloud Pro is limited to 25 events a second, and the docs give defaults of 1,000 API requests and 1,000 ingested events a second for self-hosted instances (15). The docs say a breach returns 429 and document idempotency keys on events, but give no Retry-After or backoff guidance for API clients, although the server code sets Retry-After (10). The pricing page lists a 99.99 per cent uptime SLA on Pro and 99.999 on Premium. No SLA document was found (7). The API is generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 78,
            "points": 12.68,
            "reason": "OpenAPI 3.0 spec in the public repository, 68 operations on 49 paths with 153 schemas, and the API reference is generated from it (25). llms.txt, with every documentation page also served as Markdown (10). Every operation has a description, but most are one line such as \"This endpoint retries an event delivery\" and none says when not to use it (10). 32 enums and typed request models, though `models.CreateEvent` marks no field as required (10). 58 examples. Every operation lists 400, 401 and 404, while the errors page documents four codes and one sample body, and 429 isn't in the spec (8). Dated API versions with `X-Convoy-Version`, a compatibility matrix and a per-release CHANGELOG.md. The spec's own version field reads 26.3.5 against release 26.8.0 (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 69,
            "points": 11.21,
            "reason": "List sizes are set with `perPage` (default 50), with no field selection or summaries, and event bodies come back whole (12). Cursor pagination in both directions, with filters by date range, endpoint, source and idempotency key (20). Errors are `{\"status\": false, \"message\": ...}` with conventional HTTP codes. Messages are specific, but only four codes are documented and there are no machine-readable error codes (10). `idempotency_key` on event creation plus replay and retry endpoints. Endpoint and subscription creates have no idempotency key, and the onboarding guide says to look up by `ownerId` first (15). An event needs only an endpoint id, an event type and data. SDKs for JavaScript, Python, Go and Ruby, with convoy.js last published on 13 November 2023 (12)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 53,
            "points": 9.28,
            "reason": "Bearer API keys. A project key is limited to one project, a personal key to its user's organisations, and both can be regenerated or revoked. No OAuth for API clients, and we found no per-action scopes on a key (22). Roles include a read-only project viewer, listed as paid for self-hosted instances and on Cloud Premium. Whether an API key can be issued read-only wasn't established, and deletes need no confirmation (8). Incoming webhook payloads are third-party content. The docs cover signature verification and SSRF but give no guidance for agents reading payloads (5). Every delivery attempt is logged with request and response. No audit log of API or dashboard actions was found (7). No security.txt and no SECURITY.md. GitHub private vulnerability reporting is on, one advisory was published in July 2026, and the repository runs CodeQL, OSV and Trivy workflows. The pricing page lists SOC 2, and the trust centre couldn't be read (11)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "Graded on Convoy Cloud. No x402, MPP or L402 (0). Flat plan prices are public, Pro at $99 and Premium at $499 a month, with no per-message price (10). A 14-day trial without a card, limited to 100 events a day (20). A person has to sign up in a browser to get a Cloud key (0). The self-hosted Community edition is free and `convoy bootstrap --with-api-key` prints a key without a signup, which this score doesn't count because the hosted service is what we graded."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 80,
            "points": 7,
            "reason": "v26.8.0 was tagged on 27 September 2026, 11 days before this check (30). 22 version tags between 27 June and 27 September 2026 (20). The issues page shows 34 open issues, the most recently updated on 14 September 2026 and many untouched since 2023. Support runs through a community Slack and GitHub (12). convoy-python 0.2.0 was published on 21 July 2026 and a workflow regenerates SDKs from the spec, but convoy.js on npm dates from 13 November 2023 (10). The repository has integration, end-to-end, lint, CodeQL and nightly OSV workflows. We couldn't read their current pass state (8)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 67,
            "points": 5.86,
            "note": "editorial 65, provenance 69",
            "reason": "The gateway's source is public under the Elastic Licence 2.0, which isn't an OSI licence and bars offering it as a hosted service. The OpenAPI spec still names the MPL 2.0 (20). A privacy notice dated 1 June 2023 that still cites Privacy Shield, a DPA with deletion within 60 days of termination and breach notice without undue delay, and a Cloud subscription policy with dated suspension and deletion steps. The terms name no legal entity (15). The Cloud upgrade policy promises at least 180 days' notice of major upgrades and deprecations, and breaking API changes are listed by version (20). US and EU regions are named and self-hosted telemetry is documented with an opt-out (`CONVOY_ANALYTICS_ENABLED=false`). The sub-processor list at trust.getconvoy.io didn't render for us (10)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "List sizes are set with `perPage` (default 50), with no field selection or summaries, and event bodies come back whole (12). Cursor pagination in both directions, with filters by date range, endpoint, source and idempotency key (20). Errors are `{\"status\": false, \"message\": ...}` with conventional HTTP codes. Messages are specific, but only four codes are documented and there are no machine-readable error codes (10). `idempotency_key` on event creation plus replay and retry endpoints. Endpoint and subscription creates have no idempotency key, and the onboarding guide says to look up by `ownerId` first (15). An event needs only an endpoint id, an event type and data. SDKs for JavaScript, Python, Go and Ruby, with convoy.js last published on 13 November 2023 (12).",
            "maintenance": "v26.8.0 was tagged on 27 September 2026, 11 days before this check (30). 22 version tags between 27 June and 27 September 2026 (20). The issues page shows 34 open issues, the most recently updated on 14 September 2026 and many untouched since 2023. Support runs through a community Slack and GitHub (12). convoy-python 0.2.0 was published on 21 July 2026 and a workflow regenerates SDKs from the spec, but convoy.js on npm dates from 13 November 2023 (10). The repository has integration, end-to-end, lint, CodeQL and nightly OSV workflows. We couldn't read their current pass state (8).",
            "payments": "Graded on Convoy Cloud. No x402, MPP or L402 (0). Flat plan prices are public, Pro at $99 and Premium at $499 a month, with no per-message price (10). A 14-day trial without a card, limited to 100 events a day (20). A person has to sign up in a browser to get a Cloud key (0). The self-hosted Community edition is free and `convoy bootstrap --with-api-key` prints a key without a signup, which this score doesn't count because the hosted service is what we graded.",
            "reliability": "Graded as a hosted service, Convoy Cloud. status.getconvoy.io on incident.io lists the website and the US and EU data and control planes, with data since July 2024 (20). It shows 100 per cent uptime on every component from July to October 2026 and no incidents, though the day-by-day calendar didn't load for us (30). Cloud Pro is limited to 25 events a second, and the docs give defaults of 1,000 API requests and 1,000 ingested events a second for self-hosted instances (15). The docs say a breach returns 429 and document idempotency keys on events, but give no Retry-After or backoff guidance for API clients, although the server code sets Retry-After (10). The pricing page lists a 99.99 per cent uptime SLA on Pro and 99.999 on Premium. No SLA document was found (7). The API is generally available (10).",
            "schema": "OpenAPI 3.0 spec in the public repository, 68 operations on 49 paths with 153 schemas, and the API reference is generated from it (25). llms.txt, with every documentation page also served as Markdown (10). Every operation has a description, but most are one line such as \"This endpoint retries an event delivery\" and none says when not to use it (10). 32 enums and typed request models, though `models.CreateEvent` marks no field as required (10). 58 examples. Every operation lists 400, 401 and 404, while the errors page documents four codes and one sample body, and 429 isn't in the spec (8). Dated API versions with `X-Convoy-Version`, a compatibility matrix and a per-release CHANGELOG.md. The spec's own version field reads 26.3.5 against release 26.8.0 (15).",
            "security": "Bearer API keys. A project key is limited to one project, a personal key to its user's organisations, and both can be regenerated or revoked. No OAuth for API clients, and we found no per-action scopes on a key (22). Roles include a read-only project viewer, listed as paid for self-hosted instances and on Cloud Premium. Whether an API key can be issued read-only wasn't established, and deletes need no confirmation (8). Incoming webhook payloads are third-party content. The docs cover signature verification and SSRF but give no guidance for agents reading payloads (5). Every delivery attempt is logged with request and response. No audit log of API or dashboard actions was found (7). No security.txt and no SECURITY.md. GitHub private vulnerability reporting is on, one advisory was published in July 2026, and the repository runs CodeQL, OSV and Trivy workflows. The pricing page lists SOC 2, and the trust centre couldn't be read (11).",
            "transparency": "The gateway's source is public under the Elastic Licence 2.0, which isn't an OSI licence and bars offering it as a hosted service. The OpenAPI spec still names the MPL 2.0 (20). A privacy notice dated 1 June 2023 that still cites Privacy Shield, a DPA with deletion within 60 days of termination and breach notice without undue delay, and a Cloud subscription policy with dated suspension and deletion steps. The terms name no legal entity (15). The Cloud upgrade policy promises at least 180 days' notice of major upgrades and deprecations, and breaking API changes are listed by version (20). US and EU regions are named and self-hosted telemetry is documented with an opt-out (`CONVOY_ANALYTICS_ENABLED=false`). The sub-processor list at trust.getconvoy.io didn't render for us (10)."
          },
          "sources": [
            {
              "what": "pricing and plan limits",
              "url": "https://www.getconvoy.io/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index (llms.txt)",
              "url": "https://www.getconvoy.io/docs/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "API authentication",
              "url": "https://www.getconvoy.io/docs/api-reference/authentication",
              "seen": "2026-10-08"
            },
            {
              "what": "API versioning and breaking changes",
              "url": "https://www.getconvoy.io/docs/api-reference/versioning",
              "seen": "2026-10-08"
            },
            {
              "what": "API errors",
              "url": "https://www.getconvoy.io/docs/api-reference/errors",
              "seen": "2026-10-08"
            },
            {
              "what": "pagination",
              "url": "https://www.getconvoy.io/docs/api-reference/pagination",
              "seen": "2026-10-08"
            },
            {
              "what": "rate limits",
              "url": "https://www.getconvoy.io/docs/product-manual/rate-limits",
              "seen": "2026-10-08"
            },
            {
              "what": "idempotency",
              "url": "https://www.getconvoy.io/docs/product-manual/idempotency",
              "seen": "2026-10-08"
            },
            {
              "what": "signatures",
              "url": "https://www.getconvoy.io/docs/product-manual/signatures",
              "seen": "2026-10-08"
            },
            {
              "what": "retry schedule",
              "url": "https://www.getconvoy.io/docs/glossary/retry-schedule",
              "seen": "2026-10-08"
            },
            {
              "what": "API-driven onboarding",
              "url": "https://www.getconvoy.io/docs/guides/api-onboarding",
              "seen": "2026-10-08"
            },
            {
              "what": "RBAC",
              "url": "https://www.getconvoy.io/docs/product-manual/rbac",
              "seen": "2026-10-08"
            },
            {
              "what": "paid plan list and Community limits",
              "url": "https://www.getconvoy.io/docs/business-and-enterprise/paid-features",
              "seen": "2026-10-08"
            },
            {
              "what": "SDKs and Cloud base URLs",
              "url": "https://www.getconvoy.io/docs/sdk/sdk",
              "seen": "2026-10-08"
            },
            {
              "what": "telemetry",
              "url": "https://www.getconvoy.io/docs/resources/telemetry",
              "seen": "2026-10-08"
            },
            {
              "what": "Cloud upgrade policy",
              "url": "https://www.getconvoy.io/docs/cloud/cloud-upgrade-policy",
              "seen": "2026-10-08"
            },
            {
              "what": "Cloud subscription policy",
              "url": "https://www.getconvoy.io/docs/cloud/cloud-subscription-policy",
              "seen": "2026-10-08"
            },
            {
              "what": "status page",
              "url": "https://status.getconvoy.io",
              "seen": "2026-10-08"
            },
            {
              "what": "repository (LICENSE, CHANGELOG.md, tags, workflows, OpenAPI spec), cloned",
              "url": "https://github.com/frain-dev/convoy",
              "seen": "2026-10-08"
            },
            {
              "what": "security advisory",
              "url": "https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4",
              "seen": "2026-10-08"
            },
            {
              "what": "security policy tab (none set)",
              "url": "https://github.com/frain-dev/convoy/security/policy",
              "seen": "2026-10-08"
            },
            {
              "what": "open issues",
              "url": "https://github.com/frain-dev/convoy/issues",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of use",
              "url": "https://www.getconvoy.io/legal/Terms-of-Use-Convoy.pdf",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy notice",
              "url": "https://www.getconvoy.io/legal/privacy-policy",
              "seen": "2026-10-08"
            },
            {
              "what": "DPA",
              "url": "https://www.getconvoy.io/legal/dpa",
              "seen": "2026-10-08"
            },
            {
              "what": "npm convoy.js",
              "url": "https://registry.npmjs.org/convoy.js",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI convoy-python",
              "url": "https://pypi.org/pypi/convoy-python/json",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP for getconvoy.io",
              "url": "https://rdap.identitydigital.services/rdap/domain/getconvoy.io",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the trust centre at trust.getconvoy.io and its sub-processor list render only with JavaScript, so SOC 2 status and sub-processors rest on the pricing page's claim and the DPA's link",
            "unchecked: the day-by-day incident calendar on status.getconvoy.io didn't load. The 90-day record rests on the page's 100 per cent uptime figures and its empty incident feed",
            "unchecked: the GitHub API refused us for its rate limit. Stars (2,877) come from the repository page, and the pass state of CI on main wasn't read",
            "Whether an API key can be issued with a read-only role on Convoy Cloud wasn't established from the docs",
            "No SLA document was found behind the uptime percentages on the pricing page",
            "The Cloud signup page wasn't exercised, so the no-card trial rests on the pricing page",
            "First release date not established from a 200-commit clone"
          ]
        },
        "negative": -6,
        "negativeNotes": [
          "2026-07-24. Advisory GHSA-p5vg-v7mj-f6q4, rated High. Before v26.6.8 any caller authorised on one project could read another project's source record by id, including message broker credentials in plaintext. Patched in 26.6.8 and published by the maintainers, so the deduction is reduced to 4 (https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4).",
          "2026-08-04. Until v26.7.0 the events list returned `metadata` on dynamic events, which carried the endpoint secret and custom auth headers in plaintext. The field was removed across every API version and the change is documented, so the deduction is 2 (https://www.getconvoy.io/docs/api-reference/versioning)."
        ],
        "verdict": "Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.",
        "bestFor": "A product that has to send signed webhooks to its customers' endpoints with retries, replay and a delivery log, or receive third-party webhooks and route them inward.",
        "strengths": [
          "Public OpenAPI 3.0 spec with 68 operations, plus llms.txt and Markdown copies of every documentation page",
          "Event creation accepts an `idempotency_key`, and the API has single and batch replay and retry endpoints for events and deliveries",
          "Dated API versions (current default 2025-11-24) pinned per request with the `X-Convoy-Version` header",
          "22 tagged releases between 27 June and 27 September 2026, with breaking changes listed per release in CHANGELOG.md",
          "Convoy Cloud's upgrade policy promises at least 180 days' notice of major upgrades and deprecations"
        ],
        "weaknesses": [
          "Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8",
          "Until v26.7.0 (4 August 2026) the events list returned endpoint secrets and custom auth headers in plaintext for dynamic events",
          "No security.txt and no SECURITY.md. The trust centre at trust.getconvoy.io renders only with JavaScript, so we couldn't read it",
          "The errors page documents four HTTP codes and one sample body. 429 and Retry-After aren't in the API reference",
          "Cloud needs a browser signup, and the 14-day trial allows 100 events a day, one project and one user"
        ],
        "agentNotes": [
          "Use the regional base URL, https://us.getconvoy.cloud/api/v1 or https://eu.getconvoy.cloud/api/v1. A project key works only under /projects/{projectID}/",
          "Create an endpoint, then a subscription, then the event. An event sent to an endpoint with no subscription isn't dispatched",
          "Send `idempotency_key` on every event. A repeated key creates the event but no delivery, and the key stays reserved until retention deletes the event",
          "Create projects with a personal API key and the `orgID` query parameter. The project key in that response is shown once",
          "Before retrying an endpoint or subscription create, list endpoints by `ownerId`. Idempotency keys cover event ingestion only"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.2
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 80,
          "payments": 30,
          "reliability": 92,
          "schema": 78,
          "security": 53,
          "transparency": 65
        },
        "provenanceScore": 69
      },
      "connect": {
        "install": "curl -fsSL https://getconvoy.io/install | bash",
        "http": "curl --request POST \\\n  --url https://{region}.getconvoy.cloud/api/v1/projects/\u003cproject-id\u003e/events \\\n  --header 'Authorization: Bearer \u003capi-key\u003e' \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"endpoint_id\": \"\u003cendpoint-id\u003e\", \"event_type\": \"payment.success\", \"data\": {\"status\": \"Completed\"}}'"
      },
      "letme": {
        "capability": "https://letme.dev/events.webhooks-send",
        "tool": "https://letme.dev/convoy"
      },
      "notable": [
        "The API reference is generated from an OpenAPI 3.0 spec in the repository with 68 operations across endpoints, events, subscriptions, filters, sources, portal links and deliveries (https://github.com/frain-dev/convoy/blob/main/docs/v3/openapi3.json)",
        "Advisory GHSA-p5vg-v7mj-f6q4, published 24 July 2026 and rated High, describes a cross-project read of source records with plaintext broker credentials, patched in 26.6.8 (https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4)",
        "v26.7.0 removed `metadata` from the events list because it carried the endpoint secret and custom auth headers in plaintext on dynamic events (https://www.getconvoy.io/docs/api-reference/versioning)",
        "Cloud plans are flat. Pro is $99 a month for 25 events a second with 7-day retention, Premium $499 a month, and both list an uptime SLA (https://www.getconvoy.io/pricing)",
        "The repository's LICENSE file is the Elastic Licence 2.0, which bars offering the software as a hosted service, while the OpenAPI spec's info block still names the MPL 2.0 (https://github.com/frain-dev/convoy/blob/main/LICENSE)",
        "The Community edition is limited to one user, one organisation and two projects (https://www.getconvoy.io/docs/business-and-enterprise/paid-features)",
        "status.getconvoy.io shows 100 per cent uptime from July to October 2026 on the website and on the US and EU data and control planes, with no open incidents (https://status.getconvoy.io)"
      ],
      "area": "developer",
      "details": [
        {
          "label": "Surface graded",
          "value": "Convoy Cloud's HTTP API at https://us.getconvoy.cloud/api and https://eu.getconvoy.cloud/api. The self-hosted gateway serves the same API from the same spec. No MCP server found"
        },
        {
          "label": "API",
          "value": "OpenAPI 3.0, 68 operations on 49 paths. Projects, endpoints, events, event deliveries, delivery attempts, subscriptions, filters, sources, event types, portal links, meta events, bulk onboard"
        },
        {
          "label": "Credentials",
          "value": "Bearer token. A project API key is scoped to one project. A personal API key follows its user's organisation membership and creates and lists projects with `orgID`"
        },
        {
          "label": "Sending",
          "value": "Direct, fan-out by `owner_id`, broadcast by event type, and dynamic events that carry their own endpoint URL. Events also arrive from Kafka, Amazon SQS, Google Pub/Sub and RabbitMQ"
        },
        {
          "label": "Receiving",
          "value": "Incoming projects take third-party webhooks at a source URL, verify them and route them to endpoints through subscriptions with filters"
        },
        {
          "label": "Retries",
          "value": "Linear or exponential backoff, set per project. Default backoff schedule 10 s, 30 s, 1 min, 3 min, 5 min, 10 min, 15 min. Manual, force and batch retry, single and batch replay"
        },
        {
          "label": "Signatures",
          "value": "HMAC in `X-Convoy-Signature`, hex or base64. Advanced signatures add a timestamp and several `v1` hashes so secrets can roll. An endpoint for rolling a secret is in the API"
        },
        {
          "label": "Idempotency",
          "value": "`idempotency_key` on event creation, forwarded to the receiver as `X-Convoy-Idempotency-Key`. Incoming sources can take the key from a header, body field or query parameter"
        },
        {
          "label": "Rate limits",
          "value": "Cloud Pro 25 events a second, custom on Premium. Self-hosted defaults 1,000 API requests a second and 1,000 ingested events a second, both configurable. Over the limit returns 429"
        },
        {
          "label": "Pagination",
          "value": "Cursor based with `perPage` (default 50), `next_page_cursor`, `prev_page_cursor` and `direction`. Event lists filter by date range, endpoint, source and idempotency key"
        },
        {
          "label": "Versioning",
          "value": "Dated API versions 2024-01-01, 2024-04-01 and 2025-11-24, pinned per request with `X-Convoy-Version`. Security fixes can remove a response field across every version"
        },
        {
          "label": "SDKs",
          "value": "convoy.js (npm 1.1.0, published 13 November 2023), convoy-python (PyPI 0.2.0, 21 July 2026), convoy-go v2 and convoy.rb in the docs. A repository workflow also names PHP and Java SDK repositories"
        },
        {
          "label": "Self-hosted",
          "value": "Community edition free with one user, one organisation and two projects. Needs PostgreSQL and Redis. `convoy bootstrap --with-api-key` prints a personal API key without the dashboard"
        },
        {
          "label": "Licence",
          "value": "Elastic Licence 2.0. Source available, no offering it as a hosted service and no bypassing the licence key. SDKs are MIT per npm"
        },
        {
          "label": "Status",
          "value": "status.getconvoy.io on incident.io. Website, data plane and control plane for the US and EU regions, with data since July 2024"
        },
        {
          "label": "Cloud changes",
          "value": "Minor upgrades every two weeks. Major upgrades and deprecations come with at least 180 days' notice by Slack and email, per the Cloud upgrade policy"
        }
      ],
      "unitPrices": [
        {
          "item": "Cloud Pro",
          "unit": "month",
          "usd": 99,
          "note": "25 events a second, 7-day retention"
        },
        {
          "item": "Cloud Premium",
          "unit": "month",
          "usd": 499,
          "note": "custom rate limits and retention"
        },
        {
          "item": "Self-hosted Premium licence",
          "unit": "month",
          "usd": 999,
          "note": "Community edition is free"
        }
      ],
      "provenance": {
        "legalEntity": "Frain Technologies Inc.",
        "domain": "getconvoy.io",
        "domainRegistered": "2021-09-06",
        "endpointOnVendorDomain": false,
        "terms": "https://www.getconvoy.io/legal/Terms-of-Use-Convoy.pdf",
        "privacy": "https://www.getconvoy.io/legal/privacy-policy",
        "statusPage": "https://status.getconvoy.io",
        "changelog": "https://github.com/frain-dev/convoy/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The repository's LICENSE file names Frain Technologies Inc. as licensor, and the home page footer names Frain Technologies at 2261 Market Street, San Francisco, CA 94114. The terms and privacy notice say only Convoy and its affiliates, with info@frain.dev as contact.",
          "The Cloud API answers at us.getconvoy.cloud and eu.getconvoy.cloud, a different registered domain from getconvoy.io. The vendor's own docs and OpenAPI spec name both hosts.",
          "www.getconvoy.io/.well-known/security.txt returns 404. us.getconvoy.cloud returns the dashboard's HTML at that path. The GitHub repository has no SECURITY.md but accepts private vulnerability reports.",
          "The privacy notice is dated 1 June 2023. The DPA at getconvoy.io/legal/dpa points to a sub-processor list at trust.getconvoy.io/subprocessors, which renders only with JavaScript and which we couldn't read.",
          "RDAP for getconvoy.io gives a registration date of 2021-09-06."
        ],
        "score": 69,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Frain Technologies Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "getconvoy.io, registered 2021-09-06 (5 years)",
            "points": 11,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": " is not on getconvoy.io",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Terms of service",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 5 of the 8 things a reader expects",
            "points": 7.8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.getconvoy.io",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.getconvoy.io/legal/Terms-of-Use-Convoy.pdf",
            "state": "not-read",
            "points": 10,
            "max": 10
          },
          {
            "kind": "privacy",
            "url": "https://www.getconvoy.io/legal/privacy-policy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2023-06-01",
            "words": 1855,
            "points": 7.8,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated: June 1, 2023",
                "says": "Last updated 2023-06-01"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": false
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": false
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "(\"CCPA\"), as applicable (collectively, the \"Applicable Data Protection Laws\"), the Company is acting as a processor/service provider, and the User is acting as the controller/business, as applicable."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "(ii) not sell Personal Data (as defined under the CCPA);",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "For the purposes of (i) the General Data Protection Regulation (2016/679) (\"GDPR\"), including any subordinate or implementing legislation, (ii) the EU-US Privacy Shield (\"Privacy Shield\"), and (iii) the California Consumer Privacy Act of 2018, Cal."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "The User can exercise the User's rights of access, rectification, erasure, restriction, objection, and data portability by contacting the Company at [email protected].",
                "says": "Gives an email address, hidden from our reader by the page"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Last updated: June 1, 2023"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The notice states that it does not cover content the user processes or stores through the services.",
                "quote": "This PN does not apply to any content processed and/or stored by the User when using the Services."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/convoy.json",
      "live": {
        "slug": "convoy",
        "vendorStatus": {
          "page": "https://status.getconvoy.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T18:21:55.078010278Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "frain-dev/convoy",
            "version": "v26.8.0",
            "released": "2026-09-28",
            "seenAt": "2026-10-08T16:07:07.309156702Z"
          },
          {
            "registry": "npm",
            "name": "convoy.js",
            "version": "1.1.0",
            "seenAt": "2026-10-08T16:07:02.917445318Z"
          },
          {
            "registry": "pypi",
            "name": "convoy-python",
            "version": "0.2.0",
            "released": "2023-05-16",
            "seenAt": "2026-10-08T16:07:07.117567905Z"
          }
        ],
        "githubStars": 2877,
        "npmWeekly": 2257,
        "pypiWeekly": 679,
        "securityTxt": {
          "url": "https://getconvoy.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:08.354465852Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/frain-dev/convoy/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:09.887860175Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "91084795c305"
          }
        ],
        "updatedAt": "2026-10-08T18:24:09.887860175Z"
      }
    },
    "verify": {
      "accepts": "a page on getconvoy.io or one of its subdomains, or the README of github.com/frain-dev/convoy",
      "badgeUrl": "https://www.anchorterminal.com/badges/convoy.svg",
      "body": {
        "slug": "convoy",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/convoy",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/convoy\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/convoy.svg\" alt=\"Convoy on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Convoy on Anchor Terminal](https://www.anchorterminal.com/badges/convoy.svg)](https://www.anchorterminal.com/tools/convoy)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/convoy\"\u003eConvoy on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/convoy",
    "json": "https://www.anchorterminal.com/tools/convoy.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/convoy.md",
    "slim": "https://www.anchorterminal.com/tools/convoy.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 62.2/100 · rank #308 of 629 · #5 in Event delivery \u0026 webhooks · not agent-ready · confidence medium**\n\n\n## Assessment\n\nConvoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Frain Technologies Inc. (https://www.getconvoy.io) |\n| Kind | HTTP API |\n| Category | Event delivery \u0026 webhooks (https://www.anchorterminal.com/categories/webhooks) |\n| Transport | HTTP |\n| Auth | API key · Self-serve API keys sent as a Bearer token. A project API key is scoped to one project and is returned once when the project is created, or regenerated in project settings. A personal API key, created in the dashboard's security settings, follows its user's organisation membership and creates projects. No OAuth for API clients and no partner or sales approval. On self-hosted instances `convoy bootstrap --with-api-key` prints a personal key. |\n| Pricing | Paid ($99 / mo) · Convoy Cloud has a 14-day trial without a card (one project, one user, 100 events a day), then Pro at $99 a month for 25 events a second or Premium at $499 a month. Plans are flat with a throughput limit and no per-message charge. The self-hosted Community edition is free with one user and two projects, and self-hosted Premium is $999 a month (https://www.getconvoy.io/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the docs index, the OpenAPI spec or the pricing page (checked 2026-10-08). |\n| Licence | Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use |\n| Packages | npm: `convoy.js`; pypi: `convoy-python`; go: `github.com/frain-dev/convoy-go/v2` |\n| Source | https://github.com/frain-dev/convoy |\n| Docs | https://www.getconvoy.io/docs |\n| llms.txt | https://www.getconvoy.io/docs/llms.txt |\n| Last release | 2026-09-27 |\n| GitHub stars | 2,877 (as of 2026-10-08) |\n| npm downloads / week | 2,257 |\n| PyPI downloads / week | 679 |\n| Surface graded | Convoy Cloud's HTTP API at https://us.getconvoy.cloud/api and https://eu.getconvoy.cloud/api. The self-hosted gateway serves the same API from the same spec. No MCP server found |\n| API | OpenAPI 3.0, 68 operations on 49 paths. Projects, endpoints, events, event deliveries, delivery attempts, subscriptions, filters, sources, event types, portal links, meta events, bulk onboard |\n| Credentials | Bearer token. A project API key is scoped to one project. A personal API key follows its user's organisation membership and creates and lists projects with `orgID` |\n| Sending | Direct, fan-out by `owner_id`, broadcast by event type, and dynamic events that carry their own endpoint URL. Events also arrive from Kafka, Amazon SQS, Google Pub/Sub and RabbitMQ |\n| Receiving | Incoming projects take third-party webhooks at a source URL, verify them and route them to endpoints through subscriptions with filters |\n| Retries | Linear or exponential backoff, set per project. Default backoff schedule 10 s, 30 s, 1 min, 3 min, 5 min, 10 min, 15 min. Manual, force and batch retry, single and batch replay |\n| Signatures | HMAC in `X-Convoy-Signature`, hex or base64. Advanced signatures add a timestamp and several `v1` hashes so secrets can roll. An endpoint for rolling a secret is in the API |\n| Idempotency | `idempotency_key` on event creation, forwarded to the receiver as `X-Convoy-Idempotency-Key`. Incoming sources can take the key from a header, body field or query parameter |\n| Rate limits | Cloud Pro 25 events a second, custom on Premium. Self-hosted defaults 1,000 API requests a second and 1,000 ingested events a second, both configurable. Over the limit returns 429 |\n| Pagination | Cursor based with `perPage` (default 50), `next_page_cursor`, `prev_page_cursor` and `direction`. Event lists filter by date range, endpoint, source and idempotency key |\n| Versioning | Dated API versions 2024-01-01, 2024-04-01 and 2025-11-24, pinned per request with `X-Convoy-Version`. Security fixes can remove a response field across every version |\n| SDKs | convoy.js (npm 1.1.0, published 13 November 2023), convoy-python (PyPI 0.2.0, 21 July 2026), convoy-go v2 and convoy.rb in the docs. A repository workflow also names PHP and Java SDK repositories |\n| Self-hosted | Community edition free with one user, one organisation and two projects. Needs PostgreSQL and Redis. `convoy bootstrap --with-api-key` prints a personal API key without the dashboard |\n| Licence | Elastic Licence 2.0. Source available, no offering it as a hosted service and no bypassing the licence key. SDKs are MIT per npm |\n| Status | status.getconvoy.io on incident.io. Website, data plane and control plane for the US and EU regions, with data since July 2024 |\n| Cloud changes | Minor upgrades every two weeks. Major upgrades and deprecations come with at least 180 days' notice by Slack and email, per the Cloud upgrade policy |\n| Capabilities | events.webhooks-send, events.webhooks-receive |\n| Tags | hosted, self-hosted, source-available, webhooks, api-key, openapi, llms-txt, no-card, status-page, go, python, typescript, ruby |\n| JSON | https://www.anchorterminal.com/api/v1/tools/convoy.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 92 | 18.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 78 | 12.7 |\n| Agent ergonomics | 13% | 16.2 | 69 | 11.2 |\n| Security \u0026 auth | 14% | 17.5 | 53 | 9.3 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 80 | 7.0 |\n| Transparency \u0026 trust (editorial 65, provenance 69) | 7% | 8.8 | 67 | 5.9 |\n| Negative events | up to −15 | up to −15 | 2026-07-24. Advisory GHSA-p5vg-v7mj-f6q4, rated High. Before v26.6.8 any caller authorised on one project could read another project's source record by id, including message broker credentials in plaintext. Patched in 26.6.8 and published by the maintainers, so the deduction is reduced to 4 (https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4). 2026-08-04. Until v26.7.0 the events list returned `metadata` on dynamic events, which carried the endpoint secret and custom auth headers in plaintext. The field was removed across every API version and the change is documented, so the deduction is 2 (https://www.getconvoy.io/docs/api-reference/versioning).  | -6 |\n| **Total** | | | | **62.2 → B** |\n\n### Why each score\n\n- Reliability 92: Graded as a hosted service, Convoy Cloud. status.getconvoy.io on incident.io lists the website and the US and EU data and control planes, with data since July 2024 (20). It shows 100 per cent uptime on every component from July to October 2026 and no incidents, though the day-by-day calendar didn't load for us (30). Cloud Pro is limited to 25 events a second, and the docs give defaults of 1,000 API requests and 1,000 ingested events a second for self-hosted instances (15). The docs say a breach returns 429 and document idempotency keys on events, but give no Retry-After or backoff guidance for API clients, although the server code sets Retry-After (10). The pricing page lists a 99.99 per cent uptime SLA on Pro and 99.999 on Premium. No SLA document was found (7). The API is generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 78: OpenAPI 3.0 spec in the public repository, 68 operations on 49 paths with 153 schemas, and the API reference is generated from it (25). llms.txt, with every documentation page also served as Markdown (10). Every operation has a description, but most are one line such as \"This endpoint retries an event delivery\" and none says when not to use it (10). 32 enums and typed request models, though `models.CreateEvent` marks no field as required (10). 58 examples. Every operation lists 400, 401 and 404, while the errors page documents four codes and one sample body, and 429 isn't in the spec (8). Dated API versions with `X-Convoy-Version`, a compatibility matrix and a per-release CHANGELOG.md. The spec's own version field reads 26.3.5 against release 26.8.0 (15).\n- Agent ergonomics 69: List sizes are set with `perPage` (default 50), with no field selection or summaries, and event bodies come back whole (12). Cursor pagination in both directions, with filters by date range, endpoint, source and idempotency key (20). Errors are `{\"status\": false, \"message\": ...}` with conventional HTTP codes. Messages are specific, but only four codes are documented and there are no machine-readable error codes (10). `idempotency_key` on event creation plus replay and retry endpoints. Endpoint and subscription creates have no idempotency key, and the onboarding guide says to look up by `ownerId` first (15). An event needs only an endpoint id, an event type and data. SDKs for JavaScript, Python, Go and Ruby, with convoy.js last published on 13 November 2023 (12).\n- Security \u0026 auth 53: Bearer API keys. A project key is limited to one project, a personal key to its user's organisations, and both can be regenerated or revoked. No OAuth for API clients, and we found no per-action scopes on a key (22). Roles include a read-only project viewer, listed as paid for self-hosted instances and on Cloud Premium. Whether an API key can be issued read-only wasn't established, and deletes need no confirmation (8). Incoming webhook payloads are third-party content. The docs cover signature verification and SSRF but give no guidance for agents reading payloads (5). Every delivery attempt is logged with request and response. No audit log of API or dashboard actions was found (7). No security.txt and no SECURITY.md. GitHub private vulnerability reporting is on, one advisory was published in July 2026, and the repository runs CodeQL, OSV and Trivy workflows. The pricing page lists SOC 2, and the trust centre couldn't be read (11).\n- Payments \u0026 pricing 30: Graded on Convoy Cloud. No x402, MPP or L402 (0). Flat plan prices are public, Pro at $99 and Premium at $499 a month, with no per-message price (10). A 14-day trial without a card, limited to 100 events a day (20). A person has to sign up in a browser to get a Cloud key (0). The self-hosted Community edition is free and `convoy bootstrap --with-api-key` prints a key without a signup, which this score doesn't count because the hosted service is what we graded.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 80: v26.8.0 was tagged on 27 September 2026, 11 days before this check (30). 22 version tags between 27 June and 27 September 2026 (20). The issues page shows 34 open issues, the most recently updated on 14 September 2026 and many untouched since 2023. Support runs through a community Slack and GitHub (12). convoy-python 0.2.0 was published on 21 July 2026 and a workflow regenerates SDKs from the spec, but convoy.js on npm dates from 13 November 2023 (10). The repository has integration, end-to-end, lint, CodeQL and nightly OSV workflows. We couldn't read their current pass state (8).\n- Transparency \u0026 trust 67: The gateway's source is public under the Elastic Licence 2.0, which isn't an OSI licence and bars offering it as a hosted service. The OpenAPI spec still names the MPL 2.0 (20). A privacy notice dated 1 June 2023 that still cites Privacy Shield, a DPA with deletion within 60 days of termination and breach notice without undue delay, and a Cloud subscription policy with dated suspension and deletion steps. The terms name no legal entity (15). The Cloud upgrade policy promises at least 180 days' notice of major upgrades and deprecations, and breaking API changes are listed by version (20). US and EU regions are named and self-hosted telemetry is documented with an opt-out (`CONVOY_ANALYTICS_ENABLED=false`). The sub-processor list at trust.getconvoy.io didn't render for us (10).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/convoy.md (JSON https://www.anchorterminal.com/fixes/convoy.json)\n\n### What we couldn't check\n\n- unchecked: the trust centre at trust.getconvoy.io and its sub-processor list render only with JavaScript, so SOC 2 status and sub-processors rest on the pricing page's claim and the DPA's link\n- unchecked: the day-by-day incident calendar on status.getconvoy.io didn't load. The 90-day record rests on the page's 100 per cent uptime figures and its empty incident feed\n- unchecked: the GitHub API refused us for its rate limit. Stars (2,877) come from the repository page, and the pass state of CI on main wasn't read\n- Whether an API key can be issued with a read-only role on Convoy Cloud wasn't established from the docs\n- No SLA document was found behind the uptime percentages on the pricing page\n- The Cloud signup page wasn't exercised, so the no-card trial rests on the pricing page\n- First release date not established from a 200-commit clone\n\n### Sources\n\n- pricing and plan limits: \u003chttps://www.getconvoy.io/pricing\u003e (seen 2026-10-08)\n- docs index (llms.txt): \u003chttps://www.getconvoy.io/docs/llms.txt\u003e (seen 2026-10-08)\n- API authentication: \u003chttps://www.getconvoy.io/docs/api-reference/authentication\u003e (seen 2026-10-08)\n- API versioning and breaking changes: \u003chttps://www.getconvoy.io/docs/api-reference/versioning\u003e (seen 2026-10-08)\n- API errors: \u003chttps://www.getconvoy.io/docs/api-reference/errors\u003e (seen 2026-10-08)\n- pagination: \u003chttps://www.getconvoy.io/docs/api-reference/pagination\u003e (seen 2026-10-08)\n- rate limits: \u003chttps://www.getconvoy.io/docs/product-manual/rate-limits\u003e (seen 2026-10-08)\n- idempotency: \u003chttps://www.getconvoy.io/docs/product-manual/idempotency\u003e (seen 2026-10-08)\n- signatures: \u003chttps://www.getconvoy.io/docs/product-manual/signatures\u003e (seen 2026-10-08)\n- retry schedule: \u003chttps://www.getconvoy.io/docs/glossary/retry-schedule\u003e (seen 2026-10-08)\n- API-driven onboarding: \u003chttps://www.getconvoy.io/docs/guides/api-onboarding\u003e (seen 2026-10-08)\n- RBAC: \u003chttps://www.getconvoy.io/docs/product-manual/rbac\u003e (seen 2026-10-08)\n- paid plan list and Community limits: \u003chttps://www.getconvoy.io/docs/business-and-enterprise/paid-features\u003e (seen 2026-10-08)\n- SDKs and Cloud base URLs: \u003chttps://www.getconvoy.io/docs/sdk/sdk\u003e (seen 2026-10-08)\n- telemetry: \u003chttps://www.getconvoy.io/docs/resources/telemetry\u003e (seen 2026-10-08)\n- Cloud upgrade policy: \u003chttps://www.getconvoy.io/docs/cloud/cloud-upgrade-policy\u003e (seen 2026-10-08)\n- Cloud subscription policy: \u003chttps://www.getconvoy.io/docs/cloud/cloud-subscription-policy\u003e (seen 2026-10-08)\n- status page: \u003chttps://status.getconvoy.io\u003e (seen 2026-10-08)\n- repository (LICENSE, CHANGELOG.md, tags, workflows, OpenAPI spec), cloned: \u003chttps://github.com/frain-dev/convoy\u003e (seen 2026-10-08)\n- security advisory: \u003chttps://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4\u003e (seen 2026-10-08)\n- security policy tab (none set): \u003chttps://github.com/frain-dev/convoy/security/policy\u003e (seen 2026-10-08)\n- open issues: \u003chttps://github.com/frain-dev/convoy/issues\u003e (seen 2026-10-08)\n- terms of use: \u003chttps://www.getconvoy.io/legal/Terms-of-Use-Convoy.pdf\u003e (seen 2026-10-08)\n- privacy notice: \u003chttps://www.getconvoy.io/legal/privacy-policy\u003e (seen 2026-10-08)\n- DPA: \u003chttps://www.getconvoy.io/legal/dpa\u003e (seen 2026-10-08)\n- npm convoy.js: \u003chttps://registry.npmjs.org/convoy.js\u003e (seen 2026-10-08)\n- PyPI convoy-python: \u003chttps://pypi.org/pypi/convoy-python/json\u003e (seen 2026-10-08)\n- RDAP for getconvoy.io: \u003chttps://rdap.identitydigital.services/rdap/domain/getconvoy.io\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 69/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Frain Technologies Inc. | 20/20 |\n| Domain age | getconvoy.io, registered 2021-09-06 (5 years) | 11/15 |\n| Endpoint on the vendor's domain |  is not on getconvoy.io | 0/15 |\n| Terms of service | published | 10/10 |\n| Privacy policy | read, states 5 of the 8 things a reader expects | 7.8/10 |\n| Status page | status.getconvoy.io | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe repository's LICENSE file names Frain Technologies Inc. as licensor, and the home page footer names Frain Technologies at 2261 Market Street, San Francisco, CA 94114. The terms and privacy notice say only Convoy and its affiliates, with info@frain.dev as contact.\n\nThe Cloud API answers at us.getconvoy.cloud and eu.getconvoy.cloud, a different registered domain from getconvoy.io. The vendor's own docs and OpenAPI spec name both hosts.\n\nwww.getconvoy.io/.well-known/security.txt returns 404. us.getconvoy.cloud returns the dashboard's HTML at that path. The GitHub repository has no SECURITY.md but accepts private vulnerability reports.\n\nThe privacy notice is dated 1 June 2023. The DPA at getconvoy.io/legal/dpa points to a sub-processor list at trust.getconvoy.io/subprocessors, which renders only with JavaScript and which we couldn't read.\n\nRDAP for getconvoy.io gives a registration date of 2021-09-06.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.getconvoy.io/legal/Terms-of-Use-Convoy.pdf), not read yet.\n\n\n**Privacy policy** (https://www.getconvoy.io/legal/privacy-policy), read 2026-10-08, dated 2023-06-01, states 5 of the 8 things a reader expects.\n\n- To know. Has not been updated for three years or more. \"Last updated: June 1, 2023\"\n- Gives the date it was last updated. Last updated 2023-06-01.\n- Not found in the text. Says what personal data is collected.\n- Not found in the text. Says how long data is kept.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. Gives an email address, hidden from our reader by the page.\n- Not found in the text. Says where data is transferred or stored.\n- Also in the text (2026-10-08). The notice states that it does not cover content the user processes or stores through the services. \"This PN does not apply to any content processed and/or stored by the User when using the Services.\"\n\n## Live (updated 2026-10-08 18:24 UTC)\n\n- Vendor status page: none, All Systems Operational\n- github `frain-dev/convoy` v26.8.0, released 2026-09-28\n- npm `convoy.js` 1.1.0\n- pypi `convoy-python` 0.2.0, released 2023-05-16\n- security.txt: none\n- Watching changelog \u003chttps://raw.githubusercontent.com/frain-dev/convoy/main/CHANGELOG.md\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/convoy.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Cloud Pro | $99 | per month (plan) | 25 events a second, 7-day retention |\n| Cloud Premium | $499 | per month (plan) | custom rate limits and retention |\n| Self-hosted Premium licence | $999 | per month (plan) | Community edition is free |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.0 spec with 68 operations, plus llms.txt and Markdown copies of every documentation page\n- Event creation accepts an `idempotency_key`, and the API has single and batch replay and retry endpoints for events and deliveries\n- Dated API versions (current default 2025-11-24) pinned per request with the `X-Convoy-Version` header\n- 22 tagged releases between 27 June and 27 September 2026, with breaking changes listed per release in CHANGELOG.md\n- Convoy Cloud's upgrade policy promises at least 180 days' notice of major upgrades and deprecations\n\n## Weaknesses\n\n- Advisory GHSA-p5vg-v7mj-f6q4 (24 July 2026, High) let a caller on one project read another project's source and broker credentials before v26.6.8\n- Until v26.7.0 (4 August 2026) the events list returned endpoint secrets and custom auth headers in plaintext for dynamic events\n- No security.txt and no SECURITY.md. The trust centre at trust.getconvoy.io renders only with JavaScript, so we couldn't read it\n- The errors page documents four HTTP codes and one sample body. 429 and Retry-After aren't in the API reference\n- Cloud needs a browser signup, and the 14-day trial allows 100 events a day, one project and one user\n\n## Before you call it (notes for agents)\n\n1. Use the regional base URL, https://us.getconvoy.cloud/api/v1 or https://eu.getconvoy.cloud/api/v1. A project key works only under /projects/{projectID}/\n2. Create an endpoint, then a subscription, then the event. An event sent to an endpoint with no subscription isn't dispatched\n3. Send `idempotency_key` on every event. A repeated key creates the event but no delivery, and the key stays reserved until retention deletes the event\n4. Create projects with a personal API key and the `orgID` query parameter. The project key in that response is shown once\n5. Before retrying an endpoint or subscription create, list endpoints by `ownerId`. Idempotency keys cover event ingestion only\n\n## Connect\n\nInstall:\n\n```bash\ncurl -fsSL https://getconvoy.io/install | bash\n```\n\nFirst request:\n\n```bash\ncurl --request POST \\\n  --url https://{region}.getconvoy.cloud/api/v1/projects/\u003cproject-id\u003e/events \\\n  --header 'Authorization: Bearer \u003capi-key\u003e' \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"endpoint_id\": \"\u003cendpoint-id\u003e\", \"event_type\": \"payment.success\", \"data\": {\"status\": \"Completed\"}}'\n```\n\nThrough letme (picks today, calling later): https://letme.dev/convoy. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Hookdeck | BB | 76.9 | 23 | events.webhooks-receive, events.webhooks-send | no | https://www.anchorterminal.com/tools/hookdeck.md |\n| Ably | BB | 75 | 53 | events.webhooks-send, events.webhooks-receive | no | https://www.anchorterminal.com/tools/ably.md |\n| Svix | BB | 74 | 66 | events.webhooks-send, events.webhooks-receive | no | https://www.anchorterminal.com/tools/svix.md |\n| Upstash QStash | BB | 72.3 | 90 | events.webhooks-send, events.webhooks-receive | no | https://www.anchorterminal.com/tools/upstash-qstash.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The API reference is generated from an OpenAPI 3.0 spec in the repository with 68 operations across endpoints, events, subscriptions, filters, sources, portal links and deliveries (source: \u003chttps://github.com/frain-dev/convoy/blob/main/docs/v3/openapi3.json\u003e)\n- Advisory GHSA-p5vg-v7mj-f6q4, published 24 July 2026 and rated High, describes a cross-project read of source records with plaintext broker credentials, patched in 26.6.8 (source: \u003chttps://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4\u003e)\n- v26.7.0 removed `metadata` from the events list because it carried the endpoint secret and custom auth headers in plaintext on dynamic events (source: \u003chttps://www.getconvoy.io/docs/api-reference/versioning\u003e)\n- Cloud plans are flat. Pro is $99 a month for 25 events a second with 7-day retention, Premium $499 a month, and both list an uptime SLA (source: \u003chttps://www.getconvoy.io/pricing\u003e)\n- The repository's LICENSE file is the Elastic Licence 2.0, which bars offering the software as a hosted service, while the OpenAPI spec's info block still names the MPL 2.0 (source: \u003chttps://github.com/frain-dev/convoy/blob/main/LICENSE\u003e)\n- The Community edition is limited to one user, one organisation and two projects (source: \u003chttps://www.getconvoy.io/docs/business-and-enterprise/paid-features\u003e)\n- status.getconvoy.io shows 100 per cent uptime from July to October 2026 on the website and on the US and EU data and control planes, with no open incidents (source: \u003chttps://status.getconvoy.io\u003e)\n\n## Compare\n\n- [Ably vs Convoy](https://www.anchorterminal.com/compare/ably-vs-convoy.md): BB 75 vs B 62.2\n- [Convoy vs Hookdeck](https://www.anchorterminal.com/compare/convoy-vs-hookdeck.md): B 62.2 vs BB 76.9\n- [Convoy vs Svix](https://www.anchorterminal.com/compare/convoy-vs-svix.md): B 62.2 vs BB 74\n- [Convoy vs Upstash QStash](https://www.anchorterminal.com/compare/convoy-vs-upstash-qstash.md): B 62.2 vs BB 72.3\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on getconvoy.io or one of its subdomains, or the README of github.com/frain-dev/convoy. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"convoy\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/convoy\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/convoy.svg\" alt=\"Convoy on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Convoy on Anchor Terminal](https://www.anchorterminal.com/badges/convoy.svg)](https://www.anchorterminal.com/tools/convoy)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/convoy\"\u003eConvoy on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Convoy is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/convoy-dark.png\n- Light: https://www.anchorterminal.com/assets/share/convoy-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Event delivery \u0026 webhooks",
        "url": "https://www.anchorterminal.com/categories/webhooks"
      },
      {
        "name": "Convoy",
        "url": ""
      }
    ],
    "description": "Convoy is a webhooks gateway from Frain Technologies. It sends outgoing webhooks with retries and signatures and receives incoming ones, through an HTTP API on Convoy Cloud or a self-hosted, source-available server.",
    "facts": [
      "rank #308 of 629",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Convoy",
    "image": "https://www.anchorterminal.com/assets/og/tools-convoy.png",
    "path": "/tools/convoy",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Convoy review for AI agents, grade B (62.2/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/convoy"
  },
  "tokens": {
    "markdown": 7150,
    "slim": 1980
  },
  "version": 1
}
