FlurryPORT
Every webhook, exactly as it arrived. Replay on demand.
SubscriptionAICLICI2,303 impressions#5 of its week5 comments
Comments
>log in to commentThanks Zain! the regression angle is exactly the intent: auto-replay per endpoint plus saved collections turn real production traffic into a repeatable suite you re-run on demand, no hand-written fixtures. On signatures I'll keep it short since I went deep on it in the thread with Thomas: raw bytes stored and replayed verbatim, signature headers and querystring forwarded untouched, so it passes your real verify step and lets you drive the failure paths. And yes. Replay is a first-class MCP tool call today. replay_to_target replays a captured event server-side to a registered destination, forward_to_localhost sends captures straight to your local handler (start_echo_server spins up an instant one), plus list_replay_targets / list_replay_executions / get_replay_execution to drive and inspect runs — npx -y flurryport mcp and point your editor at it. (The coming-soon piece I mentioned above is the AI-assisted transformation/recipe layer, not replay itself.)
- Zain Sheikh· 3mo ago
Auto-replay per endpoint plus saved collections basically turns captured production traffic into a regression suite, which is a nice side effect of a debugging tool.
- Zain Sheikh· 3mo ago
Byte-for-byte replay that keeps the original signature valid is the part that matters, since hand-rolled test payloads always fail verification. Does the MCP server expose replay as a tool call?
Yes — and to your exact concern: the raw body is stored and replayed byte-for-byte, never re-serialized. We read the raw bytes on capture, encrypt them at rest, and send those exact bytes back on replay (as a byte array, no JSON round-trip), so an HMAC over the payload still matches. We actually keep a diagnostic that recomputes the Stripe HMAC-SHA256 off a stored capture and checks it against the original Stripe-Signature header — that's how we confirm the round-trip stays bit-exact. Signature headers and the querystring forward verbatim. The only headers we don't copy are hop-by-hop (Content-Length, Connection, Transfer-Encoding), which the transport regenerates and which aren't part of any signature. So you can replay straight through your real verify step and exercise the failure paths. Replay fires manually or automatically as requests land (auto-replay per endpoint), and you can inspect every request and save collections to re-run to your heart's content. Coming soon (not live yet): an MCP/recipe layer where your AI helps build transformations and debug against your captures — best-effort PII redaction on what it sees, and your delivery credentials never reach it at all (it works with secret names, never values). Everything else above is shipping today.
- PDFops· 3mo ago
The replay angle is the useful bit — most webhook debugging dies because you can't re-fire the exact original request. Before I'd wire this in front of my handlers: do you preserve the raw body bytes and the original signature headers verbatim? For HMAC-signed webhooks (Stripe, GitHub, etc.) a replay is only useful if it still passes signature verification, and any re-serialization of the JSON body breaks the hash. If the raw payload survives byte-for-byte and I can replay through my real verify step, that's genuinely valuable for testing the failure paths.
FlurryPORT captures incoming webhooks byte-for-byte, stores them encrypted, and lets you replay them locally or to multiple targets.
- for
- Webhook developers, AI-agent builders, and teams debugging integrations.
- pricing
- freemium
Key features
- Raw capture — Stores every header and byte exactly as received.
- Replay modes — Replay single, batch or ordered sequences with stop-on-failure.
- Signature validation — Verifies Stripe, GitHub, Svix, Square and others before storage.
- AES-256-GCM encryption — All payloads are envelope-encrypted at rest with Azure Key Vault rotation.
- Transform & fan-out — Apply JSONata transforms and forward one capture to many targets.
- CLI MCP server — npm package provides a local server for AI agents like Claude Code or Cursor.
- Isolated endpoints — Each developer gets private capture URLs, avoiding tunnel collisions.
- Visual status cubes — Quick glance view of webhook state and delivery receipts.
Use cases
- Debug a failing Stripe webhook by replaying the exact payload to a local test server.
- Run AI-agent-driven integrations that need to keep credentials secret while accessing external APIs.
- Transform incoming GitHub webhook data and forward it to multiple internal services.
- Capture and replay production Slack messages for troubleshooting without exposing bot tokens.
FlurryPORT pricing
- Deckhand$0/mo/month1 project, 2 endpoints · 3-day capture retention · 100 captures/day · AES-256 envelope encryption
- Bosun$9/mo/month2 projects, 3 endpoints · 7-day retention · Batch & sequence replay · Live auto-forward
- First Mate$29/mo/month5 projects, 5 endpoints · 20-day retention · Increased burst limits · Collections
- Captain$99/mo/month10 projects, 15 endpoints · 45-day retention · Production-scale capacity · Capture lock
FlurryPORT vs alternatives
| Best for | Exact webhook capture & replay | API composition platform | Drag-and-drop backend building | Support automation | LLM observability |
|---|---|---|---|---|---|
| Pricing | Freemium | Free | Free | Free | Subscription |
| DevHunt upvotes | 5 | 38 | 118 | 82 | 89 |
| Launched | Jul 2026 | Jan 2023 | Jan 2023 | Mar 2024 | Jan 2023 |
- FlurryPORT vs WunderGraph: Focuses on API composition rather than raw webhook capture and replay.
- FlurryPORT vs BuildShip: Provides a visual backend builder, not a webhook capture/replay service.
- FlurryPORT vs QueryPal: Automates support workflows, whereas FlurryPORT handles low-level webhook traffic.
- FlurryPORT vs Langfuse: Observability for LLM apps, not a tool for storing and replaying webhook payloads.
FlurryPORT FAQ
Does my agent's credential ever reach the model?+
No. Credentials stay in the secret store and are applied server-side at delivery, never exposed to the model.
What does the free Deckhand plan include?+
One project, two endpoints, a three-day capture window, 100 daily captures and full AES-256-GCM encryption.
Can I keep a capture longer than the retention window?+
Yes, you can save it to a collection or lock it with the Captain plan to retain it indefinitely.
What signatures are validated before storage?+
FlurryPORT validates Stripe, GitHub, Svix and Square signatures, rejecting spoofed requests with a 401.
Is there a trial period for paid plans?+
All plans are subscription-based; the free Deckhand plan lets you try the full capture-replay flow without a trial.
How are payloads protected at rest?+
Payloads are envelope-encrypted with AES-256-GCM and keys are rotated automatically via Azure Key Vault.
Summarized by DevHunt from flurryport.io · Sep 28, 2026. Details may change; check the official site.