Back to Browse

Webhook Tester X402 MCP Server

Developer ToolsUse Caution2.0MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Test webhook endpoints — send requests, measure latency, validate responses. x402 micropayment.

About

Test webhook endpoints — send requests, measure latency, validate responses. x402 micropayment.

Remote endpoints: sse: https://webhook-tester.api.klymax402.com/mcp

Security Report

2.0
Use Caution2.0Critical Risk

This MCP server contains critical hardcoded credentials (Coinbase CDP API key and secret) embedded directly in the source code, along with a hardcoded wallet address and unvalidated environment variable usage. The payment integration logic assumes sensitive credentials are available via environment variables without proper fallback protection. While the webhook testing functionality itself is reasonably well-implemented with input validation, the credential exposure and insecure defaults represent a serious security vulnerability that could lead to unauthorized access and financial loss. Supply chain analysis found 5 known vulnerabilities in dependencies.

6 files analyzed · 16 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

Unverified package source

We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Webhook Tester API

MCP Server x402 License: MIT

Test webhook endpoints -- send POST/PUT/PATCH/DELETE with custom headers and payloads. Measure latency and TLS. Pay-per-call via x402 (USDC on Base L2) -- no API key, no signup, no rate-limit wall.

Part of the klymax402 marketplace -- 100 x402 micropayment APIs for AI agents, one wallet, USDC on Base.

Quickstart -- MCP

Add to your MCP client config (Claude Desktop, Cursor, ElizaOS, etc.):

{
  "mcpServers": {
    "webhook-tester": {
      "url": "https://webhook-tester.api.klymax402.com/mcp"
    }
  }
}

Quickstart -- HTTP (x402)

curl -X POST "https://webhook-tester.api.klymax402.com/api/test" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com"}'
# -> 402 Payment Required, with an x402 payment challenge in the response body

Any x402-aware client (@x402/fetch, x402-agent-tools, ATXP) handles the 402 -> sign -> retry cycle automatically.

Tools

ToolMethodPathPriceDescription
api_test_webhookPOST/api/test$0.005Send a test request to a webhook URL and analyze the response

api_test_webhook

Use this when you need to test a webhook endpoint by sending a request with custom headers, body, and method. Returns full response data in JSON.

Parameters

NameTypeRequiredDescription
urlstringyesWebhook URL to test (must be https)
methodstringnoHTTP method: POST, PUT, PATCH, DELETE (default: POST)
headersobjectnoCustom headers as key-value pairs
bodyobjectnoJSON body to send
timeoutnumbernoTimeout in seconds (default: 10, max: 30)

Example response:

{"url":"https://hooks.example.com/callback","method":"POST","statusCode":200,"responseBody":{"received":true},"latency":142,"tlsInfo":{"protocol":"TLSv1.3","cipher":"AES-256-GCM"},"requestSize":256,"responseSize":48}

When to use: testing webhook integrations, debugging API callbacks, validating endpoint availability, and measuring webhook response times.

Not for: web scraping (use web_scrape_to_markdown), screenshot capture (use capture_screenshot), HTTP header security audit (use network_analyze_headers).

Example agent prompts

  • "Test a webhook endpoint by sending a request with custom headers, body, and method"

Payment

  • Protocol: x402 -- HTTP-native pay-per-call, no signup, no API key
  • Network: Base L2 (eip155:8453)
  • Asset: USDC
  • Facilitator: Coinbase CDP (primary), PayAI (fallback)
  • Also reachable via ATXP (OAuth-wrapped x402, RFC 9728 protected-resource metadata)

Part of klymax402

100 x402 micropayment APIs for AI agents -- one wallet, USDC on Base, zero signup.

License

MIT

Reviews

No reviews yet

Be the first to review this server!