
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@railhook/node
Advanced tools
Node.js SDK for Railhook. No runtime dependencies.
npm install @railhook/node
import { Railhook } from '@railhook/node';
const client = new Railhook({
apiKey: process.env.RAILHOOK_API_KEY!,
baseUrl: 'https://railhook.io', // default http://localhost:8080
});
const event = await client.events.send(
{ type: 'order.completed', data: { orderId: 'ord_123', amount: 99.99 } },
'order-123-completed', // optional idempotency key
);
console.log(event.eventId, event.deliveriesCreated);
The signature covers the raw body, so read it before any JSON parser does.
import express from 'express';
import { constructEvent } from '@railhook/node';
const app = express();
app.post('/webhooks', express.raw({ type: 'application/json' }), (req, res) => {
try {
const event = constructEvent(req.body.toString(), req.headers, process.env.WEBHOOK_SECRET!);
console.log(event.eventId, event.data);
res.sendStatus(200);
} catch {
res.sendStatus(400);
}
});
verifyStandardWebhook checks the webhook-* headers instead. During a secret rotation
either secret's signature is accepted.
The client also covers endpoints, subscriptions, deliveries, consumers and portal sessions, and incoming sources and events. It does not retry: one call is one HTTP request.
Full docs: https://railhook.io/docs/tools/sdks/
npm install
npm test
npm run build
npm run smoke:live # against a running stack (make up)
MIT
FAQs
Official Node.js SDK for Railhook — reliable webhook infrastructure
The npm package @railhook/node receives a total of 1,285 weekly downloads. As such, @railhook/node popularity was classified as popular.
We found that @railhook/node demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.