Webhook Relay for Openclaw

A powerful utility that moves HTTP traffic across network boundaries, enabling secure webhook forwarding, local server tunneling, and payload debugging without opening firewall ports.

rusenask
v1.0.0
Jun 16, 2026
1
433
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install webhook-relay

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install webhook-relay using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Webhook Relay?

Webhook Relay is a highly versatile network routing and tunneling utility designed to manage HTTP traffic across different network boundaries. It provides developers with stable, public HTTPS endpoints paired with a lightweight agent, making it possible to receive external webhooks on localhost or private networks. By establishing outbound-only connections, Webhook Relay bypasses the need for complex firewall configurations or dedicated public IP addresses, simplifying local development, integration testing, and external API consumption.

By leveraging this integration alongside other Openclaw Skills, developers can expose local services securely (similar to ngrok), fan out single webhooks to multiple destinations, and rewrite HTTP request payloads on the fly using server-side JavaScript functions. Additionally, Webhook Relay provides a completely serverless, zero-configuration bin API to capture and inspect incoming payloads, enabling seamless debugging and HMAC signature verification for secure webhook handling.

Webhook Relay Use Cases

  • Receive webhooks from external providers (like Stripe or GitHub) on local development environments or private Kubernetes clusters with zero firewall configuration.
  • Expose a local web server (such as a Vite development server) or TCP service (like SSH or database ports) to the internet via a secure public tunnel.
  • Inspect, mock, and verify incoming webhook payloads using public, temporary bins without registering for an account or installing a CLI.
  • Fan out a single webhook to multiple endpoints simultaneously, such as sending notifications to Slack, Discord, and an internal data ingestion server.
  • Transform webhook payloads in transit using server-side JavaScript before forwarding them to final destinations.

How Webhook Relay Works

  1. The user configures a Webhook Relay "Bucket" which serves as a container grouping public Inputs and destination Outputs.
  2. The provider sends an HTTP request to the designated public Input URL (e.g., my.webhookrelay.com).
  3. Webhook Relay receives the request and, depending on the output configuration, either forwards it server-side to public URLs (no agent required) or streams it down an established outbound connection to a local agent.
  4. If routing to an internal destination, the running relay CLI agent receives the streamed request and forwards it to the private localhost or LAN host destination.
  5. Users can optionally apply server-side JavaScript functions to rewrite requests, inject headers, or drop payloads based on specific logic during transit.

Webhook Relay Setup

First, install the Webhook Relay CLI wrapper using the quick installation script or by downloading the binary. Ensure you have curl available in your environment to interface with the bin API.

# Install the CLI (macOS/Linux script)
curl https://raw.githubusercontent.com/webhookrelay/client/master/install.sh | bash

# Authenticate the CLI with your credentials
relay login

# Confirm successful authentication by listing buckets
relay bucket ls

To run Webhook Relay in automated environments or continuous integration servers, you can authenticate non-interactively by exporting RELAY_KEY and RELAY_SECRET as environment variables.

Webhook Relay Data Schema & Taxonomy

Webhook Relay organizes its resources inside a structured taxonomy within your account. The primary entities and configurations are described below:

Core Entities

Entity Description Key Attributes
Bucket Logical grouping container for inputs and outputs name, id
Input Public endpoint URL that receives incoming webhooks id, bucket_id, url
Output Destination where received requests are delivered name, destination, type (internal/public)
Tunnel Public hostname that proxies bi-directional HTTP/TCP traffic name, subdomain, crypto, protocol
Bin Temporary public debugging endpoint (expires in ~48h) id, requests, response

Captured Request Schema (Bin API)

Every request captured by a temporary debugging bin is formatted as a JSON object containing:

  • id: Unique, sortable ULID representing the transaction.
  • receivedAt: Unix epoch timestamp in seconds.
  • method: HTTP Verb (GET, POST, PUT, DELETE, etc.).
  • header: Map of header keys to lists of values.
  • query: Raw query string parameter.
  • body: Raw body string payload (capped at 500 KB).
  • ip: Originating IP address of the sender.
  • responseStatus: HTTP response status code sent back to the sender.

Webhook Relay Advanced Features

  • Server-Side JavaScript Functions: Rewrite payloads, modify headers, change HTTP methods, or drop requests dynamically using server-side JS functions (configured via relay function).
  • Webhook Fan-Out: Map a single public input to multiple public or internal outputs, executing parallel deliveries automatically.
  • Automated Retry Mechanism: Use --max-retries, --retry-wait-min, and --retry-wait-max flags to automatically retry deliveries when endpoints return 5xx errors.
  • HTTP Tunnel Customization: Protect public tunnels with HTTP basic authentication (--username/--password) and secure them with various TLS modes (flexible, full, full-strict, or tls-pass-through).
  • Cron Scheduled Webhooks: Configure repeating events with standard 5-field cron expressions to send automated payloads, heartbeats, or report triggers on demand.
  • HMAC Signature Verification: Verify payload integrity by performing server-side HMAC generation (SHA-256, SHA-512, MD5) on raw payload bodies using Webhook Relay endpoints.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*