Inizia
Webhook Failure Lab

Webhook Failure Lab

Verify webhook duplicates, signatures, retries and ordering in isolated local tests. Compare HTTP delivery with business evidence. Includes 18 scenarios, HTML/JSON/JUnit reports and complete English + Traditional Chinese guides.
#Ingegneria
Valutazione
Servono altre valutazioni
Venduti
0
Come si usa
Scarica

Duplicate event scenario diagram

Webhook Failure Lab

Test repeated, delayed and out-of-order webhooks before they reach customers. Run 18 bounded synthetic scenarios on an isolated local app and compare HTTP delivery with actual business effects.

US$24.99 · one-time Download · English + Traditional Chinese included. One shared codebase; no hosted service, subscription or paid API required.

What it checks

  • Sequential, concurrent and delayed duplicate delivery: the same event should cause one fulfillment.
  • Missing, wrong, tampered and expired signatures; freshly signed retries.
  • Older events arriving after completion: completed state must not regress.
  • Failures before/after processing, response timeout and bounded permanent failures.
  • Malformed JSON, incorrect content type, missing fields and asynchronous completion.

Each case reports delivery, business evidence and execution separately. Missing business evidence produces REVIEW, not PASS. Unsupported fault controls produce SKIP. Bad observation contracts produce ERROR.

For whom

Backend developers and QA engineers testing webhook idempotency, signature validation, retry handling and state transitions. Useful for regression checks after handler changes and for sharing reproducible failure evidence with teammates.

Input → output

Input: a validated JSON scenario, an explicitly authorized numeric loopback endpoint and a read-only business-state adapter scoped by run/case/entity. Credentials are generated locally for the demo; custom runs reference two named environment variables.

Example: deliver the same synthetic event twice. The fixed demo reports fulfillment count 0 → 1, with one accepted event and one duplicate. The intentionally faulty duplicate handler reports 0 → 2 and FAIL. Remove the observer and the result becomes REVIEW.

Output: standalone HTML, structured JSON, JUnit XML, Markdown summary and a scenario snapshot containing fixture hashes. Reports include attempted delivery evidence, before/after business state and assertions.

Start with the included demo

Requires Node.js 24 and pnpm. Extract the package, then run:

pnpm install --prod --frozen-lockfile --ignore-scripts
node build/cli.js doctor
node build/cli.js demo --locale en --out ./demo-en
node build/cli.js demo --locale zh-TW --out ./demo-zh
pnpm test

Dependencies require registry access on first installation. After installation, the included demo runs locally. The Stripe SDK is used only to verify synthetic signatures offline; no Stripe account, Stripe API key or Stripe API request is involved.

For your own app, follow the complete bilingual adapter guide. Run plan first; run requires the matching plan hash. This is an integration tool, not a plug-and-play test of arbitrary endpoints.

Included

Readable JavaScript core; complete English and Traditional Chinese guides, Skill instructions and changelogs; 18 scenarios; fixed and deliberately faulty local demo handlers; an independent adapter example; 19 customer self-tests; diagnostic scripts and third-party notices.

Verified release

v1.0.0 was tested on macOS 26.5.2 arm64 with Node 24.19.0: 74 regression tests, 19 packaged self-tests and 13 applicable scenarios against an independent adapter passed. Gate A repeated the three deliberate defects and their fixes plus missing-observer behavior three times: 21 isolated runs. These are product validation results, not a guarantee for your app. Linux and Windows have not been verified.

Limits and data handling

Only explicit numeric loopback HTTP targets are allowed. No remote targets, production payments, refunds, shipping actions or real customer records. No production traffic capture/replay, Stripe CLI equivalence, deployment, automatic code repair or compliance certification.

A PASS covers the supplied assertions and trustworthy adapter evidence within the bounded observation window. It cannot prove later behavior, unknown side effects or a dishonest adapter. Custom integration requires development work. The demo uses memory-only state and synthetic data; it does not contact Stripe. The tool has no telemetry. Your agent client may have its own data policy.

Reports stay in your chosen local folder. Avoid supplying real data; review reports before sharing. Credentials and raw response bodies are not intentionally written to reports. Download use is governed by the included license and Capafy terms; third-party components retain their own licenses.

Support: [email protected]. Refunds follow Capafy policy and applicable law.

Actual report screenshot

Captured from the v1.0.0 synthetic local demo; this is not a production-system validation.

Actual English synthetic demo report