Stars
Forks
Watchers
Developer links
Convoy
Convoy is an enterprise-grade webhooks gateway that manages both incoming and outgoing webhook traffic to guarantee reliable event delivery without exposing internal microservices to the public internet. Organizations deploy the platform at the edge to ingest events from message brokers such as Apache Kafka, RabbitMQ, and Google Cloud PubSub, or receive HTTP webhooks from third-party services directly. The gateway enforces delivery policies through configurable rate limiting per endpoint, circuit breaking during downstream outages, and automated retries using constant or exponential backoff with jitter. Developers can generate customer-facing webhook portals embedded via iframes, allowing end users to inspect delivery attempts, verify HMAC-SHA256 signatures, and manually replay failed events. Comprehensive security controls include static egress IP proxying to prevent server-side request forgery, automated rolling secret keys, and instant alerting via Slack or email when endpoints fail consecutively. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Elastic License 2.0 licensed.
Benefits
- Bi-Directional Edge Webhook Management
- Securely ingests third-party webhooks at the perimeter and dispatches internal events outward, protecting backend microservices from direct public internet exposure and unpredictable traffic spikes.
- Guaranteed Delivery With Intelligent Retries
- Protects downstream consumers using per-endpoint rate limits, circuit breakers, and automatic retry schedules with exponential backoff and jitter to overcome transient network drops and server outages.
- Self-Service Customer Debugging Portals
- Generates iframe-embeddable webhooks dashboards for end users, enabling direct inspection of delivery attempts, raw HTTP headers, event payloads, and manual re-triggers without contacting support.
- Hardened Egress and Secret Security
- Prevents server-side request forgery through strict URL blocklists, provides deterministic static IP egress for corporate firewalls, and automates credential rollover with rolling HMAC signing secrets.
Features
- Message Broker Ingestion
- Consumes webhook events from Apache Kafka, RabbitMQ, Amazon SQS, and Google Cloud PubSub, transforming and queuing payloads for dispatch.
- Customer-Facing Webhook Portals
- Provides embeddable iframe dashboards where end users monitor subscriptions, inspect request headers, view payloads, and trigger manual retries.
- Static Egress IP Proxy
- Routes outbound webhook traffic through dedicated forward proxies to ensure stable static IP origins and block SSRF requests.
- Payload Cryptographic Signing
- Computes HMAC-SHA256 signatures for every dispatched event, supporting dual active secret keys to facilitate zero-downtime key rotation.
- Circuit Breaker Protection
- Monitors endpoint response codes, automatically tripping circuit breakers and sending Slack or email alerts when error thresholds are exceeded.