Skip to content

v0.1.0 — production primitives

Latest

Choose a tag to compare

@Neerav-Gupta Neerav-Gupta released this 06 Jul 00:52

HookKit crosses from "test tool" to "production dependency"

All 13 packages published at 0.1.0 — no breaking changes, everything additive.

Drop-in verify middleware

@hookkit-dev/adapter-{express,fastify,hono,next} now ship production
signature-verification middleware, not just test helpers:

  • adapter-hono / adapter-next use the standard Web Crypto API
    unconditionally (never node:crypto), so the same handler runs unmodified
    on Node, Cloudflare Workers, Vercel Edge, and Deno Deploy.
  • adapter-express / adapter-fastify stay on the faster sync
    node:crypto path for Node-only servers.
  • Rejections respond with a generic error and never leak why to the
    client; pass onRejected(reason) to log the real reason server-side.

Idempotency stores

A single atomic checkAndSet(key, ttl) primitive (IdempotencyStore) —
avoids the check-then-set race that makes most webhook idempotency
implementations wrong under real concurrent traffic.

  • In-memory implementation ships in @hookkit-dev/core.
  • New packages: @hookkit-dev/idempotency-redis (atomic SET NX EX) and
    @hookkit-dev/idempotency-postgres (atomic upsert), both wireable into the
    verify middleware in one step via idempotency/idempotencyKey options.

Two new providers

  • Discord — Ed25519 via node:crypto's native support, golden-tested
    against the official discord-interactions npm package.
  • GitLab — static shared-secret token (no signing at all — GitLab's real,
    documented, weaker-than-HMAC scheme). The one deliberate exception to
    "verify against an official library," since none exists for a scheme this
    simple.
  • SDK aliases hookkit.clerk() / hookkit.resend() / hookkit.polar() for
    Svix/Standard-Webhooks-powered services — zero new adapter code.

Runtime schema-drift detection

detectSchemaDrift() flags when a real payload no longer matches the JSON
Schema HookKit knows for that event (e.g. after an undocumented provider API
change) — surfaced as a badge in the inspector and a non-fatal warning in
hookkit verify.

Capture → fixture → replay loop

The inspector's new "Save as fixture" button (and
hookkit fixtures save-from-inspector) turns a real captured request into a
fixture. A new API-version variant of an already-known event is immediately
usable via trigger/replay with zero code changes; a genuinely new event
type needs one manual step (registering it in the adapter's events map —
the fixture and manifest entry are already set up).

What's next

See docs/roadmap.md
for the backlog: more frameworks (SvelteKit, Nuxt, Remix, Lambda, Netlify,
Cloudflare Workers as an explicit target), typed payload codegen, an MCP
server, distribution tooling (compiled CLI binary + Homebrew), and the
provider long tail (PayPal, Twilio, SendGrid, and more).