Skip to content

Lobstack app

Trigger a bot from any webhook

A webhook from Stripe, GitHub, the Console or any other service can start a bot in the Lobstack app.

The app runs on your computer, and nothing on the internet can reach it. So a webhook is sent to an address on lobstack.ai instead, which holds it, and your app collects it. The app only ever asks; nothing connects to your computer. Each webhook it collects starts a run of the bot the trigger belongs to, and the webhook's contents are treated as untrusted input, the same as anything a connector returns.


Make a webhook address

  1. 1

    Sign in

    In the Lobstack app, use Sign in with Lobstack. Webhook addresses belong to your account.
  2. 2

    Add a webhook trigger

    Open a bot's triggers, add one, and choose Webhook. Give it a name you will recognise, like “Stripe payments”.
  3. 3

    Copy the address

    The app shows an address like https://www.lobstack.ai/api/hooks/<inbox id>.<token>. The part after the dot is a secret: anyone who has the address can send to it. It is shown once, because lobstack.ai keeps only a fingerprint of it. If you lose it, make a new address for the same trigger; the old one stops working.

Paste it where the webhook comes from

ServiceWhere
StripeDevelopers › Webhooks › Add endpoint. Paste the address as the endpoint URL and pick the events you want.
GitHubThe repository's Settings › Webhooks › Add webhook. Paste the address as the payload URL and set the content type to application/json.
The ConsoleConsole › Webhooks › Add endpoint › Send to my Lobstack app, then pick the trigger. The Console fills in a fresh address for it, which replaces the one the app showed you.
Anything elseAny service that can send an HTTPS POST. Any content type, as long as the body is text.

Signature headers are kept, so the bot can check that a webhook really came from where it says. For the Console, paste the endpoint's signing secret into the trigger and the app checks the x-lobstack-signature header; how that signature works is in Webhooks › Verifying the signature.


Limits

LimitWhat the sender gets
A body up to 256 KB413 above that
60 webhooks a minute and 1,000 a day, per address429 above that
The body must be text (JSON, a form, XML, plain text)415 for anything else
A wrong, deleted or made-up address404, the same answer for each
Accepted202 with { "received": true, "id": "…" }

An organization can have up to 50 webhook addresses. The address never redirects, and a GET to it answers 405. The bot's own run limits still apply: a run started by a webhook cannot use the shell or click on your screen, and connectors that move money are refused.


What is stored, and for how long

lobstack.ai keeps the body exactly as it was sent, and only these headers: content-type, user-agent, stripe-signature, x-hub-signature-256, x-github-event, x-github-delivery, x-request-id, and any header starting x-lobstack-, x-webhook- or x-signature. Other headers are dropped, and the sender's IP address is not stored with it.

It is kept until your app collects it, then the body and headers are removed. If your app does not collect it (the computer is off, or you are signed out), it waits up to 7 days and is then deleted. Deleting the trigger in the app turns its address off and deletes anything still waiting.

Your computer has to be onThe app collects webhooks while it is running and signed in. Anything sent while it is off waits for it, for up to 7 days.
Lobstack

An AI team that asks before it acts, and an API with a receipt on every call.

© LobstackXLinkedInGitHub