DominaresTools

All tools / Email & messaging

hookout

Signed webhooks out, rotating secrets in, and an SSRF guard in between.

Buy hookout for $99

One payment of $99, plus sales tax where it applies, and every future update. Delivered as a private GitHub repository you're invited to.

See it work

hookout 1.0.1dry run
hookout deliver --dry-run --file hookout/examples/subscribers.json --event order.paid --data '{"id":7}'
body: {"event":"order.paid","data":{"id":7}}
https://partner.example/hooks/orders  would send  X-Hookout-Signature: e4068e2698585b3cdf66ee127ac1e887c4d3f06ac19392c5d64cd6bca98b837f
http://169.254.169.254/latest/meta-data/  blocked
delivered=1 failed=1  (dry run, nothing was sent)

hookout check-url http://2130706433/
blocked: '2130706433' resolves to 127.0.0.1, which is not publicly routable
Dry run, nothing is really sent: hookout 1.0.1, run on 2026-10-05. The shipped example subscribers file on our test machine; --dry-run signs the event for each subscriber and sends nothing, and the second subscriber is refused because it points at a cloud metadata address.

What it does

Send HMAC-signed webhooks to URLs your customers typed in, without letting one point at your own network, and check inbound webhooks while you rotate the secret with no outage.

Signed sends
One compact JSON body, HMAC-SHA256 per subscriber, and a per-subscriber status. One failing subscriber never stops the rest.
SSRF guard
Refuses non-http(s) URLs, internal names, and any name that resolves to a non-public address, at registration and again before every send. A name that does not resolve passes registration and is refused at send time.
Pinned default sender
Resolves once, checks every address, connects to the checked addresses in the order DNS returned them, and does not follow redirects.
One reading of every URL
Backslash, whitespace and user@ URLs are refused, and stored URLs are rebuilt so any HTTP library reads them the way the guard did.
Inbound checks with rotation
Shared-secret and Twilio-style signature checks accept a comma list of secrets, comparing every candidate, and a plain-English report says when the old one can go.
A subscribers file that survives
Written atomically with mode 0600, and a damaged file is never overwritten.
Honest about its limits
One attempt per subscriber with no retries or queue, no replay protection in the signature, and a guard that judges the address you are about to contact, not what the far side answers.

What you get

hookout 1.0.1: the Python package and the hookout command, a subscribers-file sample, an example receiver with rotation, and the full test suite, with 193 automated tests.

A commercial license. Use it and change it in your own projects and your clients' projects. Don't share or resell the source. Read the license.

Every update. New versions land in the same repository; git pull to get them.

Requirements

Python 3.10 or newer. Python 3.10 or newer, standard library only.

How buying works

  1. Enter your GitHub username. You'll see the account before you pay, so you can check it's yours.
  2. Pay $99, plus any sales tax shown at checkout, on Stripe's checkout page.
  3. Accept the invitation GitHub emails you. Signed in as that account, you'll also find it at github.com/dominares-tools/hookout/invitations. Invitations expire after 7 days; you can get a new one any time.
  4. Clone and install:
    git clone https://github.com/dominares-tools/hookout.git

    Private repo: sign in to GitHub on this computer first. Run gh auth login and choose HTTPS, or give git a personal access token when it asks for a password. To use an SSH key instead, clone git@github.com:dominares-tools/hookout.git.

    python3 -m venv .venv && . .venv/bin/activate
    pip install ./hookout

Questions

Do I need GitHub?

Yes. Access is a read-only invitation to a private repository, sent to the GitHub account you choose.

Can I get a refund?

Yes, within 14 days, no questions asked. Access ends when the refund goes through. Refund policy.

Who takes the payment?

Payments are handled by Stripe, which works out sales tax. Your receipt and card statement show Link (LINK.COM*), Stripe's checkout service.

Something wrong?

Email support@dominares.org. Every buyer of a tool shares its repository, so support happens by email rather than in GitHub issues.