---
title: "Webhook Tester"
description: "Create a temporary webhook request bin and inspect method, headers, path, and body. Learn the expiry, storage, redaction, and access limits before use."
url: https://findutils.com/developers/webhook-tester/
category: developers
---

# Webhook Tester

Create a temporary webhook request bin and inspect method, headers, path, and body. Learn the expiry, storage, redaction, and access limits before use.

**Use this tool:** [Webhook Tester](https://findutils.com/developers/webhook-tester/)

## Programmatic access

- Browser-only: this tool works on a file, the DOM, or a browser API and has no REST or MCP id.

## Why use a temporary bin

Create bin asks the bin service for an id and a receive URL of the form https://bin.findutils.com/bins/{id}/in. This page lists requests for that id. Anyone with the id can inspect the bin, so keep the URL secret and use synthetic values. Analytics or ads on the page may still load.

## Webhook Testing Tips

- Treat the bin id and receive URL as secrets because either can expose captured request data.
- Use test payloads. Do not send passwords, access tokens, payment details, or personal records.
- Keep the raw body unchanged when you test a signature because whitespace can affect the digest.
- Use a slower refresh interval when events arrive rarely, or turn polling off after the request arrives.
- Remove the temporary receive URL from the provider when your test ends.

## Frequently Asked Questions

### Do I need an account?

No. FindUtils Webhook Tester does not require an account. The bin id controls inspection access, so keep it secret.

### How long is data kept?

The source defines a two-hour bin lifetime. A bin is temporary storage and must not be used as an event archive.

### Who can see a request body?

Anyone who has the bin id can inspect its captured requests. Treat the id and the complete receive URL as access secrets.

### Does FindUtils list bins?

No. FindUtils does not publish a directory of bins. This does not protect a bin after its identifier becomes known.

### What if Create bin fails?

The separate bin service can be unavailable, or the browser can fail to reach it. Do not send webhooks until the page shows a valid receive URL and expiry.

### Should I send real secrets to the bin?

No. Use synthetic values because the service stores captured requests until expiry. Anyone with the bin id can inspect the stored body and allowed headers.

### What request details can I inspect?

The page shows the method, path, receive time, size, content type, allowed headers, and body text. Bodies above 64 KiB are clipped by the service.

### How often does the page refresh?

Choose a 2, 5, or 10 second interval. Turn automatic polling off after the required request arrives.

### Can the tool replay a captured webhook?

No. The tool captures and displays requests only. Use an HTTP request tool or the provider test function to send a new request.

### Can I delete a bin from the page?

No manual delete control is available on the page. Bins expire automatically, but expiry does not make sensitive test data safe.

## Related Tools

- [HTTP Request Builder](https://findutils.com/developers/http-request-builder/)
- [HAR to cURL](https://findutils.com/developers/har-to-curl/)
- [JSON Formatter](https://findutils.com/developers/json-formatter/)
