Ingest · validate · queue · deliver

One ingest.
Eight destinations.
No backend on the form.

HTML form or JSON webhook. Hookwal validates, queues, and runs a pipeline: Postgres, MySQL, SMTP, Telegram, Slack, Discord, HTTP, or disk. Secrets never touch the browser.

Self-hosted or cloud HMAC · CAPTCHA · honeypot Retries + DLQ
contact.html → hookwal → postgres + telegram

What they paste

<form action="https://hooks.hookwal.app/form/token_a91f2c"
      method="POST">
  <input name="name" required>
  <input name="email" type="email">
  <textarea name="message"></textarea>
  <button>Send</button>
</form>

Pipeline

hook_contact · 2 actions
1. postgres_insert contact_leads ← Ana Ruiz 2. telegram_message New contact — ana@estudio.com
queued → 202
HMACAES-256-GCMSSRF shield SQLite queueTurnstileReplay + DLQ

Three steps. Destination stays server-side.

The browser only knows a public form URL. Credentials, chat IDs, and inboxes live encrypted in Hookwal.

1

Create a connection

Save Postgres, MySQL, SMTP, or a Telegram bot. Slack, Discord and HTTP keep the URL on the action. AES-256-GCM at rest.

2

Create an endpoint

Whitelist domains, optional HMAC, CAPTCHA, honeypot, schema and mapping. Attach any mix of the 8 engine actions. Copy /form or /hook.

3

Paste and forget

POST returns 202. SQLite queue, backoff retries, dead-letter. Replay the whole pipeline from Events.

One ingest. Any destination.

These are the action types the Go worker actually runs. Stack them on one endpoint.

✉️

send_email

SMTP to / subject / HTML body. Templates like {{ payload.email }}.

✈️

telegram_message

bot_token connection. chat_id + HTML text.

🐘

postgres_insert

Parameterized INSERT. table + column mapping whitelist.

🐬

mysql_insert

Same mapping model against MySQL.

🔗

http_request

GET/POST/PUT, custom headers, outbound HMAC signing.

💬

slack_notification

Incoming webhook URL + text. SSRF-guarded.

🎮

discord_notification

Discord webhook URL, content from the payload.

💾

save_payload

Atomic JSON write under storage/payloads/…

Built like an engine, sold like a form tool.

Two ingest paths/form/{token} for HTML. /hook/{token} for JSON apps.
Origin lockallowed_domains rejects posts from sites you did not whitelist.
Spam pathHoneypot + Turnstile / reCAPTCHA. Bots get a fake success.
Schema + mappingValidate types/email/length, then transform with {{ upper(payload.name) }}, uuid(), now().
HMAC in and outVerify X-Signature on ingest. Sign outbound HTTP with X-Webhook-Signature.
Queue + SSRFRetries, DLQ, replay. Outbound HTTP cannot hit private IPs.
Architecture

Queue in SQLite. Deliver anywhere.

Ingest on /form and /hook. Validate, transform, enqueue. Workers run the pipeline with retry and DLQ.

POST /form/{token}ingest
POST /hook/{token}json
HMAC · CAPTCHA · honeypot · schemaguards
SQLite queue · retry · DLQqueue
8 actions · AES-256-GCM credsdeliver
Ecosystem

Four surfaces, one engine.

The same Go binary. Interfaces split like a real SaaS.

1

Customer portal

Endpoints, connections, events, replay. What you see after login.

2

Engine

Single binary. SQLite. Workers. No Redis required.

3

Admin API

POST /admin/hooks, credentials, jobs, replay. Bearer token.

4

Billing

Cloud plans, invoices, on-prem quote — same pattern as a mail SaaS portal.

Developer API

JSON in. Pipeline out.

POST /hook/{token} for apps. POST /form/{token} for HTML. Admin routes behind a bearer token.

POST /hook/{token}
curl -X POST https://hookwal.com/hook/token_a91f2c \
  -H "Content-Type: application/json" \
  -H "X-Signature: sha256=…" \
  -d '{
    "name": "Ana",
    "email": "ana@estudio.com",
    "message": "hello"
  }'

Simple cloud plans.

Start free. Upgrade when the form is converting.

Free

$0 /mo
  • 50k events
  • 2 endpoints
  • All 8 action types
  • 3-day logs
Get started

Pro

$79 /mo
  • 5M events
  • Custom domain
  • 30-day retention
  • Priority support
Go Pro
Enterprise · On-premise

Install it on your own infrastructure.

Single binary, Ansible, your SQLite (or later HA). White-label the portal. Price on request.

Price on request
Request quote

Linux binary

amd64 / ARM. systemd unit in the repo.

Ansible

Playbook already deploys nginx + the engine.

No software caps

Events, endpoints and retention limited by hardware.

White-label

Portal and public form URLs under your domain.

Ship the form. Keep the secrets.

Create a workspace or talk to us about on-prem.

Open panel