Skip to main content
Introducing packages.sweber.dev
Documentation menuCLI

CLI

Generate secrets, sign and verify bodies, send test events and receive webhooks locally.

The package ships a vector command.

npx @sweberdev/vector secret
CommandWhat it does
vector secretPrints a new whsec_ secret
vector sign --secret <s> [--id <id>] [--timestamp <unix>] [--file <path>]Prints the three webhook-* headers for a body from stdin or a file
vector verify --secret <s> --id <id> --timestamp <unix> --signature <sig> [--file <path>]Checks a signature; exits with 1 if it does not match
vector send <url> --secret <s> [--type <event>] [--data <json>] [--allow-private]Sends one signed event to a URL and prints the status
vector listen [--port 4000] [--secret <s>]Starts a local receiver that prints every request, and verifies it when a secret is given (401 if it does not match)

Examples

Test your receiver while you build it:

vector send http://localhost:3000/api/webhooks --secret whsec_... --allow-private \
  --type invoice.paid --data '{"invoiceId":"inv_123"}'

Watch what your app sends in development:

vector listen --port 4000 --secret whsec_...

and register http://localhost:4000/ as an endpoint with urlPolicy: { allowPrivateNetworks: true }.

vector verify ignores the age of the timestamp unless you pass --tolerance <seconds>, so you can check requests copied from a log.