# Convoy (slim) > Convoy is a webhooks gateway from Frain Technologies. It sends outgoing webhooks with retries and signatures and receives incoming ones, through an HTTP API on Convoy Cloud or a self-hosted, source-available server. - Full: https://www.anchorterminal.com/tools/convoy.md (~7,150 tokens) · this version ~1,980 tokens · JSON https://www.anchorterminal.com/tools/convoy.json · canonical https://www.anchorterminal.com/tools/convoy - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 62.2/100 · rank #308 of 629 · #5 in Event delivery & webhooks · not agent-ready · confidence medium** Assessment: Convoy Cloud runs the same HTTP API as the self-hosted gateway, with a public OpenAPI spec of 68 operations, project-scoped keys, idempotency keys on events and replay endpoints. Two credential exposures were fixed in July and August 2026, one published as a high-severity advisory. Cloud access needs a browser signup, and the trial allows 100 events a day. ## Facts - Kind: HTTP API · vendor: Frain Technologies Inc. · category: Event delivery & webhooks · legal entity: Frain Technologies Inc. · provenance 69/100 - Local only (HTTP): npm `convoy.js`, pypi `convoy-python`, go `github.com/frain-dev/convoy-go/v2` - Auth: API key · pricing: Paid · x402: no · licence: Elastic Licence 2.0 for the gateway (source available, not an OSI licence). The convoy.js SDK is MIT per npm. Convoy Cloud is a proprietary hosted service under Convoy's terms of use - Probe metrics: not measured yet (probes haven't run) - Surface graded: Convoy Cloud's HTTP API at https://us.getconvoy.cloud/api and https://eu.getconvoy.cloud/api. The self-hosted gateway serves the same API from the same spec. No MCP server found - API: OpenAPI 3.0, 68 operations on 49 paths. Projects, endpoints, events, event deliveries, delivery attempts, subscriptions, filters, sources, event types, portal links, meta events, bulk onboard - Credentials: Bearer token. A project API key is scoped to one project. A personal API key follows its user's organisation membership and creates and lists projects with `orgID` - Sending: Direct, fan-out by `owner_id`, broadcast by event type, and dynamic events that carry their own endpoint URL. Events also arrive from Kafka, Amazon SQS, Google Pub/Sub and RabbitMQ - Receiving: Incoming projects take third-party webhooks at a source URL, verify them and route them to endpoints through subscriptions with filters - Retries: Linear or exponential backoff, set per project. Default backoff schedule 10 s, 30 s, 1 min, 3 min, 5 min, 10 min, 15 min. Manual, force and batch retry, single and batch replay - Signatures: HMAC in `X-Convoy-Signature`, hex or base64. Advanced signatures add a timestamp and several `v1` hashes so secrets can roll. An endpoint for rolling a secret is in the API - Idempotency: `idempotency_key` on event creation, forwarded to the receiver as `X-Convoy-Idempotency-Key`. Incoming sources can take the key from a header, body field or query parameter - Rate limits: Cloud Pro 25 events a second, custom on Premium. Self-hosted defaults 1,000 API requests a second and 1,000 ingested events a second, both configurable. Over the limit returns 429 - Pagination: Cursor based with `perPage` (default 50), `next_page_cursor`, `prev_page_cursor` and `direction`. Event lists filter by date range, endpoint, source and idempotency key - Versioning: Dated API versions 2024-01-01, 2024-04-01 and 2025-11-24, pinned per request with `X-Convoy-Version`. Security fixes can remove a response field across every version - SDKs: convoy.js (npm 1.1.0, published 13 November 2023), convoy-python (PyPI 0.2.0, 21 July 2026), convoy-go v2 and convoy.rb in the docs. A repository workflow also names PHP and Java SDK repositories - Self-hosted: Community edition free with one user, one organisation and two projects. Needs PostgreSQL and Redis. `convoy bootstrap --with-api-key` prints a personal API key without the dashboard - Licence: Elastic Licence 2.0. Source available, no offering it as a hosted service and no bypassing the licence key. SDKs are MIT per npm - Status: status.getconvoy.io on incident.io. Website, data plane and control plane for the US and EU regions, with data since July 2024 - Cloud changes: Minor upgrades every two weeks. Major upgrades and deprecations come with at least 180 days' notice by Slack and email, per the Cloud upgrade policy - Prices: Cloud Pro $99 per month (plan); Cloud Premium $499 per month (plan); Self-hosted Premium licence $999 per month (plan) - Scores: Reliability 92, Performance pending, Schema & documentation 78, Agent ergonomics 69, Security & auth 53, Payments & pricing 30, Task success pending, Maintenance & community 80, Transparency & trust 67 · negative events -6 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted service, Convoy Cloud. · Schema & documentation, OpenAPI 3.0 spec in the public repository, 68 operations on 49 paths with 153 schemas, and the API reference is generated from it (25). · Agent ergonomics, List sizes are set with `perPage` (default 50), with no field selection or summaries, and event bodies come back whole (12). · Security & auth, Bearer API keys. · Payments & pricing, Graded on Convoy Cloud. · Maintenance & community, v26.8.0 was tagged on 27 September 2026, 11 days before this check (30). · Transparency & trust, The gateway's source is public under the Elastic Licence 2.0, which isn't an OSI licence and bars offering it as a hosted service. - Sources: 28, open questions: 7, both in the full twin - Capabilities: events.webhooks-send, events.webhooks-receive - JSON: https://www.anchorterminal.com/api/v1/tools/convoy.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/convoy.svg` or a link to https://www.anchorterminal.com/tools/convoy from a page on getconvoy.io or one of its subdomains, or the README of github.com/frain-dev/convoy, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use the regional base URL, https://us.getconvoy.cloud/api/v1 or https://eu.getconvoy.cloud/api/v1. A project key works only under /projects/{projectID}/ 2. Create an endpoint, then a subscription, then the event. An event sent to an endpoint with no subscription isn't dispatched 3. Send `idempotency_key` on every event. A repeated key creates the event but no delivery, and the key stays reserved until retention deletes the event 4. Create projects with a personal API key and the `orgID` query parameter. The project key in that response is shown once 5. Before retrying an endpoint or subscription create, list endpoints by `ownerId`. Idempotency keys cover event ingestion only ## Connect ```bash curl -fsSL https://getconvoy.io/install | bash ``` ```bash curl --request POST \ --url https://{region}.getconvoy.cloud/api/v1/projects//events \ --header 'Authorization: Bearer ' \ --header 'Content-Type: application/json' \ --data '{"endpoint_id": "", "event_type": "payment.success", "data": {"status": "Completed"}}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/convoy ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Hookdeck | BB | 76.9 | events.webhooks-receive, events.webhooks-send | https://www.anchorterminal.com/tools/hookdeck.min.md | | Ably | BB | 75 | events.webhooks-send, events.webhooks-receive | https://www.anchorterminal.com/tools/ably.min.md | | Svix | BB | 74 | events.webhooks-send, events.webhooks-receive | https://www.anchorterminal.com/tools/svix.min.md | | Upstash QStash | BB | 72.3 | events.webhooks-send, events.webhooks-receive | https://www.anchorterminal.com/tools/upstash-qstash.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)