Inbound webhooks · MIT self-host

Swap one URL.
Stop losing webhook events.

koto7 built this after losing logistics webhooks. Paste Tuma's URL into Stripe, GitHub, or EasyPost. The event is on disk before we ack the provider. Retries, Issues, and replay run on your infra.

See how it works · Stripe · GitHub · EasyPost · MIT · Docker Compose

quickstart
# clone, then:
cd deploy
docker compose up --build

Console:  http://localhost
Webhook:  http://localhost/e/your-path

# Before
Stripe ──► your-app.com/webhooks/stripe

# After
Stripe ──► tuma/e/your-path ──► your-app.com/webhooks/stripe
                      verify · dedup · retry · replay

How it works

Three steps. Same mental model as Hookdeck.

No SDK. No code changes. One URL swap in your provider's dashboard.

[01]

Create a connection

Pick a source — Stripe, GitHub, EasyPost, generic HMAC, or internal. Tuma gives you a unique inbound URL and a signing secret.

[02]

Paste into your provider

Put Tuma's webhook URL and signing secret into Stripe, GitHub, or EasyPost. Set your destination URL — where events should land in your app.

[03]

Replay from Issues

Handler was down? The failure shows in Issues while Tuma keeps retrying. Fix your app, inspect the payload, and replay — one event or in bulk.

inbound proxy flow

verify · dedup · retry · replay — open Issues when your handler was down

Console

Everything visible. Nothing buried in logs.

A React dashboard ships with the stack — no separate observability setup required for day-to-day ops.

Connections

Source-to-destination pipes with 24h stats — delivered count, p95 latency, open issues. Status pills: Delivering, Degraded, or Failing.

Metrics

Platform-wide throughput, failure rate, p95, and hourly charts. Per-connection breakdown. Grafana on port 3001 for deeper Prometheus ops.

Issues

A failed delivery shows up in Issues, with the status code. Fix the destination and replay. A later successful attempt clears it.

Why Tuma

Hookdeck-simple inbound reliability — MIT self-hosted, Temporal-backed.

Same URL-swap idea as Hookdeck, without cloud-only lock-in. Narrower scope than Convoy — inbound only, one compose stack, genuinely MIT with no license key for core features.

Self-hostable

docker compose up --build in deploy/. Payloads and headers are encrypted in your Postgres. MIT licensed. Want someone else to run it? Join the managed waitlist.

Replay when it matters

Issues isn't a graveyard — it's a queue you drain from the console. Fix the destination, replay, and delivery resumes from durable history.

Durable by design

If the process dies mid-request, the webhook is already on disk. Delivery is at-least-once, not exactly-once. Dedupe on X-Tuma-Delivery-Id or your own business key. Retries run on Temporal, which is one more piece to operate.

Observable out of the box

In-app Metrics plus bundled Prometheus and Grafana. Go API, Temporal worker, Postgres, React UI — one compose file, no external SaaS dependencies.

Compare

Self-hostable Hookdeck. Simpler than Convoy.

Not a price war — Hookdeck has a real free tier and Convoy Community is free to self-host. Tuma wins on where your payloads live, license terms, and scope. Tuma v1 is early; we don't claim maturity or scale parity with either.

Tuma vs Hookdeck

Same inbound job — different deployment model. Hookdeck Event Gateway is cloud-only; Tuma is first-class self-host.

Hookdeck Tuma
Self-host No — cloud only Yes — MIT
Setup Sign up → paste URL docker compose up
Entry price $0 tier, then from $39/mo MIT, you run it
Data location Their cloud Your Postgres, your infra
Maturity Years, SOC2, transforms, CLI v1 OSS — Connections, Issues, replay

Tuma vs Convoy

Convoy is a multi-tenant gateway for inbound and outbound. Tuma is inbound-only — one stack, actually MIT.

Convoy Tuma
Scope Inbound + outbound gateway Inbound only (v1)
Complexity API, workers, scheduler, socket One compose stack
Self-host license Community: source-available. Premium: $999/mo license Full v1 MIT — no license key
Mental model Event bus for platforms Provider → you pipe
Best for Sending webhooks to your customers Receiving Stripe, GitHub, EasyPost reliably

Competitor pricing verified Aug 25, 2026 — hookdeck.com/pricing, getconvoy.io/pricing. Convoy's core gateway is source-available under Frain's license, not MIT — only their client SDKs are MIT.

Pricing

Run it yourself. Or get on the list.

Self-host is the product you can run today. If you try it and want the same thing managed, join the waitlist.

OPEN SOURCE

MIT

You run the stack

  • ✓ Connections, signature verification, inbound dedup
  • ✓ Retries, Issues, UI replay (single + bulk)
  • ✓ Payload encryption, alert rules, Metrics, Grafana
  • ✓ Community support via GitHub
View on GitHub

MANAGED

Waitlist

We run the stack

  • ✓ Same product, after you've tried self-host
  • ✓ Instant ingress URL — paste into Stripe
  • ✓ Connections, Metrics, Issues, alerts
  • ✓ No Compose to keep alive
Join managed waitlist

Built for

Hookdeck-shaped teams

You want URL-swap simplicity but payloads can't live in someone else's cloud. Honest at-least-once semantics, durable retries via Temporal.

Convoy evaluators

You only receive webhooks — you don't need outbound delivery or a multi-tenant gateway. Actually MIT, no $999/mo license for basics.

Logistics & shipping

EasyPost tracking and shipment events into your stack — same retry and Issues flow as payments, self-hosted in your Postgres.

Ops-critical inbound

Stripe, GitHub, EasyPost, or any signed POST — one URL, one console, replay from Issues. Try the live playground with bundled simulators.

Managed

Liked self-host? Get on the managed list.

Clone it and run Compose today. If you want the same stack hosted, leave an email. No date, no price — just the list.

tuma-demo.koto7.dev/playground · github.com/koto7-io/koto7-tuma