CLI
The verihook CLI comes with the package. Run it with npx verihook.
simulate
Section titled “simulate”Sends a correctly signed webhook to your server, with no provider account needed:
npx verihook simulate stripe --url http://localhost:3000/webhooks/stripenpx verihook simulate github --event issuesnpx verihook simulate whatsapp --secret meta_app_secretnpx verihook simulate stripe --curl # print a curl command insteadlisten
Section titled “listen”Runs a local relay that verifies each incoming webhook, prints its headers and body, and forwards it to your app:
npx verihook listen stripe --forward-to http://localhost:3000/webhooks/stripe --secret whsec_...npx verihook listen github -p 8080 --forward-to http://localhost:4000/api/githubPoint a tunnel (ngrok, Cloudflare Tunnel) or the provider’s own forwarding tool at the relay’s port.
Options
Section titled “Options”| Option | Description |
|---|---|
--url <url> |
Where simulate sends the webhook. |
--forward-to <url> |
Where listen forwards verified webhooks. |
-p, --port <port> |
Port for listen (default 8080). |
--secret <key> |
Signing secret. |
--event <type> |
Event name, e.g. GitHub’s x-github-event. |
--curl |
Print a curl command instead of sending. |
--allow-remote |
Allow non-local targets. |
Safety
Section titled “Safety”- Without
--allow-remote(orVERIHOOK_ALLOW_REMOTE=true), the CLI warns before sending to non-local hosts. - Cloud metadata endpoints, link-local addresses and their alternative encodings are blocked, as are non-HTTP protocols. This is defense in depth, not a substitute for network isolation.
- Secrets and signature headers are redacted in the terminal output.