Lobstack app
Trigger a bot from any webhook
A webhook from Stripe, GitHub, the Console or any other service can start a bot in the Lobstack app.
The app runs on your computer, and nothing on the internet can reach it. So a webhook is sent to an address on lobstack.ai instead, which holds it, and your app collects it. The app only ever asks; nothing connects to your computer. Each webhook it collects starts a run of the bot the trigger belongs to, and the webhook's contents are treated as untrusted input, the same as anything a connector returns.
Make a webhook address
- 1
Sign in
In the Lobstack app, use Sign in with Lobstack. Webhook addresses belong to your account. - 2
Add a webhook trigger
Open a bot's triggers, add one, and choose Webhook. Give it a name you will recognise, like “Stripe payments”. - 3
Copy the address
The app shows an address likehttps://www.lobstack.ai/api/hooks/<inbox id>.<token>. The part after the dot is a secret: anyone who has the address can send to it. It is shown once, because lobstack.ai keeps only a fingerprint of it. If you lose it, make a new address for the same trigger; the old one stops working.
Paste it where the webhook comes from
| Service | Where |
|---|---|
| Stripe | Developers › Webhooks › Add endpoint. Paste the address as the endpoint URL and pick the events you want. |
| GitHub | The repository's Settings › Webhooks › Add webhook. Paste the address as the payload URL and set the content type to application/json. |
| The Console | Console › Webhooks › Add endpoint › Send to my Lobstack app, then pick the trigger. The Console fills in a fresh address for it, which replaces the one the app showed you. |
| Anything else | Any service that can send an HTTPS POST. Any content type, as long as the body is text. |
Signature headers are kept, so the bot can check that a webhook really came from where it says. For the Console, paste the endpoint's signing secret into the trigger and the app checks the x-lobstack-signature header; how that signature works is in Webhooks › Verifying the signature.
Limits
| Limit | What the sender gets |
|---|---|
| A body up to 256 KB | 413 above that |
| 60 webhooks a minute and 1,000 a day, per address | 429 above that |
| The body must be text (JSON, a form, XML, plain text) | 415 for anything else |
| A wrong, deleted or made-up address | 404, the same answer for each |
| Accepted | 202 with { "received": true, "id": "…" } |
An organization can have up to 50 webhook addresses. The address never redirects, and a GET to it answers 405. The bot's own run limits still apply: a run started by a webhook cannot use the shell or click on your screen, and connectors that move money are refused.
What is stored, and for how long
lobstack.ai keeps the body exactly as it was sent, and only these headers: content-type, user-agent, stripe-signature, x-hub-signature-256, x-github-event, x-github-delivery, x-request-id, and any header starting x-lobstack-, x-webhook- or x-signature. Other headers are dropped, and the sender's IP address is not stored with it.
It is kept until your app collects it, then the body and headers are removed. If your app does not collect it (the computer is off, or you are signed out), it waits up to 7 days and is then deleted. Deleting the trigger in the app turns its address off and deletes anything still waiting.