Webhook Relay
Webhook and API infrastructure with SOC 2 Type II, SSO and audit logs
Our role
Designed and developed for the client: webhook forwarding and replay, tunnels, and the audit and access-control surface.
What it is
Webhook and API infrastructure
Industry
Developer tools
Live at
webhookrelay.com
Public traction
About $3.8K/month in reported revenue
Indie Hackers, as of September 2026
Receives, forwards and replays webhooks to public and private endpoints, tunnels to local environments, and gives teams the audit trail and access controls enterprise buyers ask for.
The problem
Webhooks fail quietly. An endpoint goes down, the provider gives up after its retries, and the calls that were dropped are noticed later by whoever reconciles the numbers. Meanwhile developers need those calls on a laptop, and the enterprise buyer needs to know who saw what — three problems usually answered by three separate pieces of software.
The first call
We separated the delivery problem from the trust problem. Receiving, forwarding and replaying is infrastructure and had to be dull and reliable; access control and the audit trail is what makes that infrastructure sellable to a company with a security review. Both belonged in the product, and neither could complicate the other.
What we built
A relay that receives, forwards and replays webhooks to public and private endpoints, tunnels them to a local environment for development, and records who did what. Access controls, single sign-on and audit logs sit alongside, so a team that adopts it for convenience can keep it through procurement.
How they run today
Deliveries are visible and replayable, so a failed call is a click rather than an incident report. Developers point a tunnel at their own machine, and the security questionnaire is answered by the product instead of by a spreadsheet.
What changed
Missed events stopped being discovered by customers. The tool that made local development easier is the same one that survives the enterprise review, which is rarely true of either category on its own.
Screens
Services behind it
- API & System IntegrationConnect CRMs, ERPs, payments, SaaS platforms and internal systems, reliably.REST APIs, Webhooks, Payments, Gmail and Google Calendar
- Cloud / DevOpsAWS, Azure and GCP: CI/CD, deployment automation, monitoring and infrastructure that scales.CI/CD, Infrastructure as code, Monitoring, Incident response
- Cybersecurity & AI SecurityProtect SaaS, APIs, cloud, data and AI systems, including apps built with AI coding tools.Application security, API security, Vulnerability scanning, Auth hardening
Not sure where to start?
Describe the problem in a few lines. You get a straight answer on what we would build and how long it takes.