webhook-site

Installation
SKILL.md

webhook.site

Hosted OAST collector + request inspector. Visiting webhook.site mints a unique token of the form https://webhook.site/<uuid>; every HTTP request and DNS query (via the matching *.dnshook.site subdomain) to that token is recorded with full headers, body, source IP, geolocation, and timing, and surfaced in a Web UI, JSON API, and (with whcli) a CLI stream that can forward or execute on each event.

Use it as the public callback endpoint for any blind vulnerability class, OAuth/SAML round-trip inspection, webhook integration debugging, or a temporary HTTPS relay into a local service during authorized engagements.

Scope Guard

  • Confirm authorization in writing before pointing any target application, OAuth flow, or callback at webhook.site. Captured requests can contain tokens, cookies, PII, and credentials.
  • Treat the token URL like a secret — anyone who knows it can read every request. Use the "Protect with password" / "Login required" features on paid plans for sensitive captures.
  • For long-running or multi-operator engagements, use a paid token (persistent, higher limits) or self-host the open-source webhook.site server on owned infrastructure.
  • Free anonymous tokens expire after 7 days of inactivity and cap at 100 requests / 10 MB body — fine for OAST PoCs, not for sustained collection.
  • Webhook.site is third-party SaaS: the operator (Simon Fredsted / webhook.site GmbH) sees every payload. Do not route customer production traffic, regulated data, or live credentials through it without a contractual agreement.
  • For DNS exfil that must not transit a third party, prefer self-hosted interactsh or an authoritative server you control.

When to Pick webhook.site

Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
webhook-site — aeondave/malskill