
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
anyhook-mcp
Advanced tools
AnyHook MCP server, gives AI agents eyes on webhooks (inspect, replay, mock, verify) for Stripe, GitHub, OpenAI, Anthropic, LangChain, and more.
An MCP server that gives AI agents eyes on webhooks, inspect events, replay deliveries, mock signed payloads, create apps. Designed for the 45-second AI handler workflow.
Apache 2.0 · npm i -g anyhook-mcp
No API key needed to start:
claude mcp add anyhook -- npx -y anyhook-mcp
Then ask your agent to run anyhook_quickstart, it creates a free relay
endpoint + API key instantly (no signup), and this MCP session auto-connects.
All account tools (events, replay, apps) work immediately. The response includes
a claim_url to keep the endpoint permanently.
Drop this MCP server into Claude Desktop / Cursor / Claude Code and your agent can:
anyhook_apps_list, see every app in your AnyHook account with its inbound URLanyhook_apps_create, spin up a new app from a promptanyhook_events, list recent events, filter by app / statusanyhook_inspect, pull a single event's headers, body, signature statusanyhook_replay, re-send a stored event to its destinations (does not burn quota)anyhook_undelivered, list events that never reached a destinationanyhook_replay_failed, bulk-replay every failed event for an appanyhook_mock, generate a signed Stripe / GitHub / Slack payload for local handler testinganyhook_verify, verify any incoming signature against your secretanyhook_providers, list every webhook provider AnyHook supportsThe inbound URL an app gives you accepts webhook POSTs and also answers provider
setup handshakes automatically: Meta's GET carrying hub.mode=subscribe gets its
hub.challenge echoed back, even before the app is configured, so the URL can be
registered in the Meta App Dashboard first and wired up after.
Two modes:
| Mode | When | What works |
|---|---|---|
| remote | ANYHOOK_API_KEY is set | All tools above, live against your AnyHook account |
| local | No API key | Provider toolkit (mock / verify / providers) + an in-memory store you can simulate events into. Useful for trying it out before signing up. |
npm install -g anyhook-mcp
# or run without installing
npx -y anyhook-mcp
Get an API key from https://anyhook.net/dashboard/settings/api-keys. Keys start with ahk_live_.
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"anyhook": {
"command": "npx",
"args": ["-y", "anyhook-mcp"],
"env": {
"ANYHOOK_API_KEY": "ahk_live_xxxxxxxx"
}
}
}
}
Restart Claude Desktop. The tools appear under the hammer icon.
Open Settings → MCP → Add new MCP server. Or edit ~/.cursor/mcp.json:
{
"mcpServers": {
"anyhook": {
"command": "npx",
"args": ["-y", "anyhook-mcp"],
"env": {
"ANYHOOK_API_KEY": "ahk_live_xxxxxxxx"
}
}
}
}
claude mcp add anyhook -e ANYHOOK_API_KEY=ahk_live_xxxxxxxx -- npx -y anyhook-mcp
Or edit ~/.claude/mcp.json directly with the same structure as above.
The same server is hosted at https://anyhook.net/mcp (streamable HTTP,
stateless). Use it from claude.ai custom connectors, ChatGPT, or any client
that speaks HTTP, nothing to install:
{ "mcpServers": { "anyhook": { "url": "https://anyhook.net/mcp" } } }
Auth per request: send Authorization: Bearer ahk_live_..., or connect
keyless and call anyhook_quickstart, it returns an api_key you then pass
as an argument on account tool calls (the transport is stateless, so the
session can't hold it for you).
Skip the env var:
{
"mcpServers": {
"anyhook": {
"command": "npx",
"args": ["-y", "anyhook-mcp"]
}
}
}
The agent gets anyhook_mock, anyhook_verify, anyhook_providers, anyhook_simulate, anyhook_events (against memory store), and anyhook_inspect (against memory store). Useful for "generate me a signed Stripe payment_intent.succeeded and POST it to localhost:3000" flows during local dev.
Triage a failing endpoint:
"Show me undelivered events for the
stripe-prodapp from the last hour, then replay them."
The agent calls anyhook_undelivered then anyhook_replay for each, surfacing the responses inline.
Create an app for a new integration:
"Make a new AnyHook app called
replicate-video-jobs, sourcegeneric, point it athttps://my-app.vercel.app/api/replicate-callback."
Calls anyhook_apps_create, returns the inbound URL you paste into Replicate.
Sanity-check a signature failure:
"Here's an inbound payload from Stripe that AnyHook is rejecting. Verify the signature manually with secret
whsec_xxx."
Calls anyhook_verify with the supplied headers + body + secret, returns valid: false plus the failure reason.
Mock a webhook for local testing:
"Generate a Stripe
payment_intent.succeededevent and POST it to http://localhost:3000/api/webhooks/stripe."
Calls anyhook_mock with targetUrl set; returns the request that was sent + your handler's response.
| Var | Required | Default | Purpose |
|---|---|---|---|
ANYHOOK_API_KEY | for remote mode | - | ahk_live_* from https://anyhook.net/dashboard/settings/api-keys |
ANYHOOK_API_BASE | no | https://anyhook.net | Override for self-hosted AnyHook deployments |
AI agents have been blind to their own webhook infrastructure. They can write the integration code, but once an event misbehaves in production they can't see it, you tell them what happened. With this MCP server, Claude / Cursor can read the actual event log, replay deliveries, debug signature failures, and even spin up new apps. It closes the loop between writing webhook code and operating it.
Apache-2.0 © AnyHook
FAQs
AnyHook MCP server, gives AI agents eyes on webhooks (inspect, replay, mock, verify) for Stripe, GitHub, OpenAI, Anthropic, LangChain, and more.
The npm package anyhook-mcp receives a total of 69 weekly downloads. As such, anyhook-mcp popularity was classified as not popular.
We found that anyhook-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.