Skip to content
TryWebhook
New URL

Last updated

Terms of service

A free tool with no accounts needs fewer rules than most, but it needs some. This is what you agree to by using TryWebhook, in language meant to be read rather than skipped.

The deal

TryWebhook gives you disposable webhook URLs so you can see what a system is actually sending. It costs nothing, asks nothing of you, and is paid for by advertising. In exchange: use it for debugging and not for harming anyone, and accept that it comes with no warranty, no support obligation and no promise that it will be running tomorrow.

Using the service means you accept these terms. If you do not, do not use it — there is no account to close.

What this is, and what it is not

It is a debugging tool. A URL you create here is a temporary inspection endpoint with a short, enforced lifetime.

It is not:

  • Storage. Everything expires 7 days after the last request it received, and 30 days after creation regardless. Do not keep anything here that you need.
  • Production infrastructure. It does not forward, relay, queue or retry anything to your servers. Pointing a live payment or order webhook here means those events land in a debugging tool and nowhere else.
  • Private. Anyone who has your URL can read every request it captured. There is no password because there is no account.
  • A security product. The signature verifier is a debugging aid. A green result here is not an authorisation decision — verify signatures in your own server with your own code.

No account means no ownership

Whoever holds a webhook URL controls it. We have no way to establish that you created one, so we cannot restore a URL you have lost, transfer one away from someone else, or prove to a third party that a URL was yours. Keep it somewhere you will find it, and treat it as a secret.

Acceptable use

Do not use TryWebhook, or any URL created on it, to:

  • collect credentials, card numbers, one-time codes or any other data from people who have been misled about where their information is going — a URL here as the target of a fake login form is the single most common abuse of tools like this;
  • host, distribute or stage malware, exploits, or any file intended to compromise a device;
  • exfiltrate data from a system you do not control, or act as a command-and-control or beacon endpoint;
  • store or transmit anything illegal in your jurisdiction or ours, including material that sexually exploits children, which is reported to the relevant authority without exception;
  • send other people's personal data that you have no lawful basis to send, or any regulated category of data — health records, cardholder data, government identifiers — to an endpoint with no access control;
  • impersonate us, or suggest that a URL on this domain is an official endpoint of any company;
  • attempt to read, enumerate, guess or brute-force webhook URLs you were not given, or otherwise reach data that is not yours;
  • attack the service — denial of service, load testing without permission, probing for vulnerabilities in a way that degrades it for others, or working around rate limits;
  • run it as free production infrastructure: automated bulk creation of URLs, sustained high-throughput traffic, or building a product whose backend is this service.

If you have found a security flaw, we would genuinely like to hear about it — write tohello@trywebhook.com before doing anything that affects other people's data.

Rate limits and fair use

The service runs inside fixed platform limits, and one person's traffic is everyone else's capacity. We rate-limit request ingestion and URL creation, cap how much of each body is stored, and cap how many requests each URL keeps. We may tighten any of those, or block a source outright, without notice. Requests refused for rate limiting get an HTTP 429 and aRetry-After header; they are not stored.

The data you send

You are responsible for what arrives at your URLs. By pointing a system here you confirm you are entitled to send that data to a third-party service with no access control, and you agree to indemnify us against claims arising from data you caused to be sent.

We do not inspect payloads as a matter of course. We may read a specific request when investigating an abuse report, complying with a legal obligation, or diagnosing a fault that cannot be diagnosed otherwise. What is stored, and for how long, is set out in theprivacy policy.

Availability

Best effort, and nothing more. There is no service level agreement, no uptime commitment and no scheduled maintenance window. The service may be slow, unavailable, changed, restricted or permanently discontinued at any time, and captured requests may be lost before they expire. Anything you would be upset to lose does not belong here.

Suspension and deletion

We may delete any webhook URL and its contents, and block any sender or visitor, at any time, with or without notice — immediately where there is credible evidence of abuse. Because there is no account, there is nothing to appeal to and nothing to reinstate: create a new URL and carry on, or write to abuse@trywebhook.com if you believe a deletion was a mistake.

Advertising

Advertising pays for the service, which is why there is no paid tier, no signup wall and no feature held back for subscribers. Ads appear on content pages only, never in the inspector. You are free to use an ad blocker; nothing here is gated on ads loading, and we will not nag you about it.

Intellectual property

The site, its code, its design and its written guides belong to us. You may read them, link to them and quote reasonable extracts with attribution; do not republish them wholesale, and do not use them to train a model that reproduces them.

The data you send to your URLs remains yours. We claim no rights over it beyond what is needed to store and display it back to you.

Stripe, GitHub, Shopify, Razorpay, Slack, Twilio, Paddle and every other product named on this site are trademarks of their respective owners. Their names are used to describe compatibility. None of them sponsor, endorse or are affiliated with TryWebhook.

No warranty

The service is provided as is and as available, without warranty of any kind, express or implied, including fitness for a particular purpose, accuracy and non-infringement. We do not warrant that captured requests are complete, that they faithfully represent what a sender transmitted, that a signature verification result is correct, or that the generated code samples are suitable for production use. Check anything that matters against the sender's own delivery log and your own implementation.

Limitation of liability

To the fullest extent the law allows, we are not liable for any indirect, incidental, special or consequential loss, nor for lost profits, lost revenue, lost data, missed webhooks, or a failed integration or deployment, arising from your use of or inability to use this service — even if the possibility was obvious.

Our total aggregate liability for any claim relating to the service is limited to the amount you have paid to use it, which is nothing. Where the law of your country does not permit some of these exclusions, they do not apply to you and the rest still do; nothing here limits liability that cannot lawfully be limited, and nothing here affects your statutory consumer rights.

Changes to these terms

We may change these terms. The date at the top of the page moves when we do, and continuing to use the service after that means you accept the new version. There is no mailing list to announce it on, because we do not have your email address.

Governing law

These terms are governed by the laws of India, and the courts ofIndia have exclusive jurisdiction over any dispute — except where the mandatory law of your country of residence gives you the right to bring proceedings locally, which this does not take away.

Contact

General enquiries: hello@trywebhook.com. Abuse:abuse@trywebhook.com or the reporting page.

The rest of the small print