Releases: Neerav-Gupta/HookKit
Release list
v0.1.0 — production primitives
HookKit crosses from "test tool" to "production dependency"
All 13 packages published at 0.1.0 — no breaking changes, everything additive.
Drop-in verify middleware
@hookkit-dev/adapter-{express,fastify,hono,next} now ship production
signature-verification middleware, not just test helpers:
adapter-hono/adapter-nextuse the standard Web Crypto API
unconditionally (nevernode:crypto), so the same handler runs unmodified
on Node, Cloudflare Workers, Vercel Edge, and Deno Deploy.adapter-express/adapter-fastifystay on the faster sync
node:cryptopath for Node-only servers.- Rejections respond with a generic error and never leak why to the
client; passonRejected(reason)to log the real reason server-side.
Idempotency stores
A single atomic checkAndSet(key, ttl) primitive (IdempotencyStore) —
avoids the check-then-set race that makes most webhook idempotency
implementations wrong under real concurrent traffic.
- In-memory implementation ships in
@hookkit-dev/core. - New packages:
@hookkit-dev/idempotency-redis(atomicSET NX EX) and
@hookkit-dev/idempotency-postgres(atomic upsert), both wireable into the
verify middleware in one step viaidempotency/idempotencyKeyoptions.
Two new providers
- Discord — Ed25519 via
node:crypto's native support, golden-tested
against the officialdiscord-interactionsnpm package. - GitLab — static shared-secret token (no signing at all — GitLab's real,
documented, weaker-than-HMAC scheme). The one deliberate exception to
"verify against an official library," since none exists for a scheme this
simple. - SDK aliases
hookkit.clerk()/hookkit.resend()/hookkit.polar()for
Svix/Standard-Webhooks-powered services — zero new adapter code.
Runtime schema-drift detection
detectSchemaDrift() flags when a real payload no longer matches the JSON
Schema HookKit knows for that event (e.g. after an undocumented provider API
change) — surfaced as a badge in the inspector and a non-fatal warning in
hookkit verify.
Capture → fixture → replay loop
The inspector's new "Save as fixture" button (and
hookkit fixtures save-from-inspector) turns a real captured request into a
fixture. A new API-version variant of an already-known event is immediately
usable via trigger/replay with zero code changes; a genuinely new event
type needs one manual step (registering it in the adapter's events map —
the fixture and manifest entry are already set up).
What's next
See docs/roadmap.md
for the backlog: more frameworks (SvelteKit, Nuxt, Remix, Lambda, Netlify,
Cloudflare Workers as an explicit target), typed payload codegen, an MCP
server, distribution tooling (compiled CLI binary + Homebrew), and the
provider long tail (PayPal, Twilio, SendGrid, and more).
v0.0.3 — fix broken package publishing
Fix: packages are now actually installable
0.0.2 was published with plain npm publish, which silently skipped two
pnpm-only transforms that the package.jsons rely on:
publishConfigoverrides never applied — every package'smain/exports
pointed at TypeScript source (./src/index.ts) instead of the builtdist/
output, breakingrequire/importfor real consumers.workspace:*ranges never rewritten — every package depending on
another@hookkit-dev/*package (sdk,core,cli,inspector, all
adapter-*) still listed it asworkspace:*, an unresolvable range outside
this monorepo.npm install/pnpm addfailed outright with
EUNSUPPORTEDPROTOCOL/ERR_PNPM_WORKSPACE_PKG_NOT_FOUNDfor every
consumer.
scripts/publish-packages.mjs now publishes with pnpm publish, which
performs both transforms correctly. No runtime behavior changed — verified
with a real npm install @hookkit-dev/sdk from the registry after publishing.
All 11 packages bumped to 0.0.3: core, fixtures, sdk, cli,
inspector, relay, adapter-express, adapter-fastify, adapter-next,
adapter-hono, adapter-nest.