Skip to content

Releases: Neerav-Gupta/HookKit

v0.1.0 — production primitives

Choose a tag to compare

@Neerav-Gupta Neerav-Gupta released this 06 Jul 00:52

HookKit crosses from "test tool" to "production dependency"

All 13 packages published at 0.1.0 — no breaking changes, everything additive.

Drop-in verify middleware

@hookkit-dev/adapter-{express,fastify,hono,next} now ship production
signature-verification middleware, not just test helpers:

  • adapter-hono / adapter-next use the standard Web Crypto API
    unconditionally (never node:crypto), so the same handler runs unmodified
    on Node, Cloudflare Workers, Vercel Edge, and Deno Deploy.
  • adapter-express / adapter-fastify stay on the faster sync
    node:crypto path for Node-only servers.
  • Rejections respond with a generic error and never leak why to the
    client; pass onRejected(reason) to log the real reason server-side.

Idempotency stores

A single atomic checkAndSet(key, ttl) primitive (IdempotencyStore) —
avoids the check-then-set race that makes most webhook idempotency
implementations wrong under real concurrent traffic.

  • In-memory implementation ships in @hookkit-dev/core.
  • New packages: @hookkit-dev/idempotency-redis (atomic SET NX EX) and
    @hookkit-dev/idempotency-postgres (atomic upsert), both wireable into the
    verify middleware in one step via idempotency/idempotencyKey options.

Two new providers

  • Discord — Ed25519 via node:crypto's native support, golden-tested
    against the official discord-interactions npm package.
  • GitLab — static shared-secret token (no signing at all — GitLab's real,
    documented, weaker-than-HMAC scheme). The one deliberate exception to
    "verify against an official library," since none exists for a scheme this
    simple.
  • SDK aliases hookkit.clerk() / hookkit.resend() / hookkit.polar() for
    Svix/Standard-Webhooks-powered services — zero new adapter code.

Runtime schema-drift detection

detectSchemaDrift() flags when a real payload no longer matches the JSON
Schema HookKit knows for that event (e.g. after an undocumented provider API
change) — surfaced as a badge in the inspector and a non-fatal warning in
hookkit verify.

Capture → fixture → replay loop

The inspector's new "Save as fixture" button (and
hookkit fixtures save-from-inspector) turns a real captured request into a
fixture. A new API-version variant of an already-known event is immediately
usable via trigger/replay with zero code changes; a genuinely new event
type needs one manual step (registering it in the adapter's events map —
the fixture and manifest entry are already set up).

What's next

See docs/roadmap.md
for the backlog: more frameworks (SvelteKit, Nuxt, Remix, Lambda, Netlify,
Cloudflare Workers as an explicit target), typed payload codegen, an MCP
server, distribution tooling (compiled CLI binary + Homebrew), and the
provider long tail (PayPal, Twilio, SendGrid, and more).

v0.0.3 — fix broken package publishing

Choose a tag to compare

@Neerav-Gupta Neerav-Gupta released this 05 Jul 22:02

Fix: packages are now actually installable

0.0.2 was published with plain npm publish, which silently skipped two
pnpm-only transforms that the package.jsons rely on:

  • publishConfig overrides never applied — every package's main/exports
    pointed at TypeScript source (./src/index.ts) instead of the built dist/
    output, breaking require/import for real consumers.
  • workspace:* ranges never rewritten — every package depending on
    another @hookkit-dev/* package (sdk, core, cli, inspector, all
    adapter-*) still listed it as workspace:*, an unresolvable range outside
    this monorepo. npm install / pnpm add failed outright with
    EUNSUPPORTEDPROTOCOL / ERR_PNPM_WORKSPACE_PKG_NOT_FOUND for every
    consumer.

scripts/publish-packages.mjs now publishes with pnpm publish, which
performs both transforms correctly. No runtime behavior changed — verified
with a real npm install @hookkit-dev/sdk from the registry after publishing.

All 11 packages bumped to 0.0.3: core, fixtures, sdk, cli,
inspector, relay, adapter-express, adapter-fastify, adapter-next,
adapter-hono, adapter-nest.