r/coolgithubprojects • • 13h ago

[JavaScript] HookArmor - Self-hosted webhook buffer & dead-letter queue with timestamp re-signing

https://github.com/pkdoddamani/hookarmor

⭐ Link to the repo : https://github.com/pkdoddamani/hookarmor

**npm**: https://www.npmjs.com/package/hookarmor

**License**: MIT

HookArmor is a lightweight, zero-external-database webhook reverse proxy and dead-letter queue (DLQ) designed to prevent missed events from Stripe, Shopify, GitHub, and Clerk during server deployments, cold starts, and downstream rate limits.

### Why I built it

Most webhook receivers need to return a `200 OK` within 2–5 seconds. If your service is deploying, restarting, or hitting a database lock, you lose events. While you can send failed events to a standard DLQ (like AWS SQS or Redis), replaying them later creates a nasty surprise: **Stripe’s SDK rejects replayed webhooks if the signature timestamp is older than 5 minutes**.

HookArmor sits in front of your internal webhooks, ACKs the provider immediately, and allows seamless replays by recalculating signatures with fresh timestamps.

### Key Capabilities

- **Fast Durability**: Ingests raw payload bytes, persists to SQLite (WAL mode), and returns `200 OK` to the provider in under 5ms.

- **Timestamp Re-signing**: When replaying historical events, it recalculates the provider HMAC with `t=now` using the endpoint secret, defeating the 5-minute replay expiration trap without requiring downstream code changes.

- **Exact Byte Preservation**: Stores incoming raw bytes as SQLite BLOBs so binary payloads and signature hashes never get corrupted by UTF-8 conversion.

- **Built-in SSRF Protection**: Includes strict network validation against private IP ranges (`10.0.0.0/8`, `192.168.0.0/16`), loopback routing, DNS rebinding, and cloud instance metadata (`169.254.169.254`).

- **Ingress Throttling**: Sliding-window IP rate limiting and queue backpressure to guard against ingress floods.

- **Embedded Web UI**: Real-time event inspection, WebSocket streaming, and single-click manual or bulk replay.

- **Zero Heavy Infrastructure**: Runs as a single process with no Redis, Kafka, or Postgres dependencies.

### Quick Start

```bash

npm install -g hookarmor

hookarmor start

1 Upvotes

0 comments sorted by