Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -481,6 +481,27 @@
"ordinal"
]
},
{
"name": "pagerduty-webhooks",
"description": "Receive and verify PagerDuty V3 webhooks (outbound webhook subscriptions created via the /webhook_subscriptions REST API). Use when setting up a PagerDuty webhook handler, debugging X-PagerDuty-Signature verification, or handling events like incident.triggered, incident.acknowledged, incident.resolved, incident.reassigned, incident.priority_updated, incident.annotated, incident.responder.added or service.updated. PagerDuty signs with HMAC-SHA256 over the RAW body, lowercase hex (Base16), in the X-PagerDuty-Signature header, which can carry MULTIPLE comma-separated `v1=` signatures for zero-downtime secret rotation. There is no timestamp and no replay window. Not PagerDuty Events API v1/v2 (that is inbound to PagerDuty), not V1/V2 webhook extensions, not PagerTree, not Pagerly, not Opsgenie, not incident.io.",
"source": "./skills/pagerduty-webhooks",
"strict": false,
"skills": [
"./"
],
"category": "integration",
"license": "MIT",
"author": {
"name": "Hookdeck",
"email": "phil@hookdeck.com"
},
"repository": "https://github.com/hookdeck/webhook-skills",
"homepage": "https://github.com/hookdeck/webhook-skills/tree/main/skills/pagerduty-webhooks",
"keywords": [
"webhooks",
"pagerduty"
]
},
{
"name": "paymob-webhooks",
"description": "Receive and verify Paymob webhook callbacks (transaction callbacks). Use when setting up Paymob webhook handlers, debugging HMAC-SHA512 signature verification, or handling payment transaction states like success, refund, void, and auth/capture from the Transaction Processed Callback.",
Expand Down
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -123,6 +123,7 @@ Skills for receiving and verifying webhooks from specific providers. Each includ
| [Ordinal](https://docs.tryordinal.com/integrations/webhooks/introduction) | [`ordinal-webhooks`](skills/ordinal-webhooks/) | Receive Ordinal (tryordinal.com) social-media content planning webhooks — there is **no signature, HMAC or signing secret**, so authenticate with a **static custom header you set yourself** via the webhook's `headers` field (e.g. `X-Webhook-Secret`) using a constant-time compare that fails closed, then unwrap the `{ type, data, createdAt }` envelope for `post.published`, `post.publish_failed`, `post.approval.requested`, `post.comment.created` and `social_profile.reconnect_needed`. Not Bitcoin Ordinals |
| [Oura](https://cloud.ouraring.com/v2/docs#tag/Webhook-Subscription-Routes) | [`oura-webhooks`](skills/oura-webhooks/) | Complete the Oura subscription handshake, verify `x-oura-signature` (HMAC-SHA256 over `timestamp + body`, UPPERCASE), handle sleep, daily_readiness, daily_activity, and workout events |
| [Paddle](https://developer.paddle.com/webhooks/overview) | [`paddle-webhooks`](skills/paddle-webhooks/) | Verify Paddle webhook signatures, handle subscription and billing events |
| [PagerDuty](https://docs.pagerduty.com/developer/webhooks-overview) | [`pagerduty-webhooks`](skills/pagerduty-webhooks/) | Verify PagerDuty V3 webhook subscriptions: `X-PagerDuty-Signature` carries one or MORE comma-separated `v1=<hex>` HMAC-SHA256 digests over the raw body (multiple entries = zero-downtime secret rotation, so accept a match against ANY of them), with no timestamp or nonce and therefore no replay window; de-duplicate on `X-Webhook-Id`, respond 202 inside the 5s budget, and handle all 30 `incident.*` / `service.*` event types |
| [PayPal](https://developer.paypal.com/api/rest/webhooks/) | [`paypal-webhooks`](skills/paypal-webhooks/) | Verify PayPal webhook signatures (RSA-SHA256 with cert), handle payment, subscription, and order events |
| [PayPro Global](https://developers.payproglobal.com/docs/integrate-with-paypro-global/webhook-ipn/) | [`paypro-global-webhooks`](skills/paypro-global-webhooks/) | Verify PayPro Global IPN webhooks (form-encoded): `SIGNATURE` (SHA256 over `ORDER_ID`+`ORDER_STATUS`+`ORDER_TOTAL_AMOUNT`+`CUSTOMER_EMAIL`+`VALIDATION_KEY`+`TEST_MODE`+`IPN_TYPE_NAME`) and `HASH` (MD5 of `ORDER_ID`+`SecretKey`), handle `OrderCharged`, `OrderRefunded`, and `SubscriptionChargeSucceed` events |
| [Paymob](https://developers.paymob.com/paymob-docs/developers/webhook-callbacks-and-hmac) | [`paymob-webhooks`](skills/paymob-webhooks/) | Verify Paymob transaction callbacks (HMAC-SHA512 hex over 20 ordered fields, delivered as the `?hmac=` query param — not a header, not the raw body), read transaction state from `success`/`is_refunded`/`is_voided`/`is_capture` booleans |
Expand Down
Loading
Loading