@octokit/webhooks

Verify, parse, and route GitHub webhook events in Node.js with full TypeScript types

SDK
npm
v14.2.0
349 stars
MIT License

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
63 /100 Good
Development Activity 48
Maintenance 44
Community 80
Maturity 60
Momentum 20

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
73 /100 Good
Architecture 74
Code Quality 78
Innovation 68
Learning Curve 72

@octokit/webhooks is the official Octokit toolset for receiving and handling GitHub webhook events in Node.js. It verifies incoming webhook signatures, parses the payload against generated TypeScript types for every GitHub event and action, and dispatches to event-specific listeners so you never have to hand-write payload validation or event-name branching logic.

It ships framework-agnostic middleware for both Node’s http server and web-standard Request/Response environments (Deno, Bun, Cloudflare Workers), plus a receiver you can wire directly into an existing Express, Fastify, or serverless handler. Types are generated from GitHub’s official OpenAPI webhook schemas, so payload shapes stay in sync with GitHub’s own event definitions release over release.

What You Get

  • Cryptographic signature verification of incoming webhook payloads via @octokit/webhooks-methods
  • Generated TypeScript types for every GitHub webhook event and action, sourced from GitHub’s official OpenAPI webhook schema
  • An event-emitter API (.on(eventName, handler)) for registering typed handlers per event and action
  • Node.js middleware for wiring directly into an http/Express server
  • Web-standard middleware (Request/Response) for Deno, Bun, and edge runtimes like Cloudflare Workers
  • A verifyAndReceive() helper for manually verifying and dispatching a payload outside the built-in middleware

Common Use Cases

  • Building a GitHub App or bot that reacts to repository events (pushes, PR opens, issue comments) with typed payload access
  • Running webhook receivers on edge platforms (Cloudflare Workers, Deno Deploy) using the web-standard middleware instead of Node’s http module
  • Securely verifying that incoming webhook requests actually originated from GitHub before processing them
  • Building CI/CD or ChatOps automation that listens for specific GitHub event/action combinations and triggers workflows

Under The Hood

Architecture: The package centers on src/index.ts, which composes the Octokit event-emitter (from octokit’s shared webhooks-methods verification layer) with generated payload types in src/generated to expose a single Webhooks class; verify-and-receive.ts handles the actual signature-check-then-dispatch flow, while src/middleware/node and src/middleware/web provide two separate adapter layers so the same core verification/dispatch logic can sit behind either Node’s http.IncomingMessage or a standard web Request object.

Tech Stack: Written in TypeScript (97% of the codebase) and built with esbuild plus tsc for type declarations, it depends on @octokit/openapi-webhooks-types for auto-generated payload shapes, @octokit/webhooks-methods for HMAC signature verification, and @octokit/request-error for consistent error objects; releases are automated via semantic-release reading conventional commits.

Code Quality: Tests run under Vitest with separate unit and integration suites (test/unit, test/integration) plus fixture-driven payload tests (test/fixtures), and the project additionally validates itself against Node’s native test runner, Bun, and Deno test runners to guarantee cross-runtime behavior; a pretest lint step (Prettier) gates every test run.

API Design: The public API is a small, familiar event-emitter shape (webhooks.on('push', handler)) that will feel immediately familiar to Node developers, with the heavy lifting of type-safety handled transparently through generated types rather than requiring manual payload casting.

Used by 6 apps in this directory

TypeScript
76%
AGPL 3.0

Abby

Developer Tools · Product Management

166

Statically typed feature flags, remote config, and A/B testing with framework-native SDKs for TypeScript teams.

View details
31
Repo Health
70
Technical
64
Dependency
Built with
TypeScript 76%
MDX 18%
Updated 1 years ago
TypeScript
96%
MIT

deepseek-harness

AI Agents · AI Development · Developer Tools

237,945

An open-source, plugin-based agent harness from DeepSeek AI that runs coding and automation agents across web, desktop, CLI, and SDK surfaces.

View details
81
Repo Health
89
Technical
74
Dependency
Built with
TypeScript 96%
Updated 1 weeks ago
TypeScript
98%
Other

Dokploy

Devops · Hosting Control Panel · Security

37,543

Self-hosted PaaS that deploys apps and databases on your own VPS using Docker, Traefik, and multi-build-system orchestration

View details
88
Repo Health
76
Technical
64
Dependency
Built with
TypeScript 98%
Updated 2 weeks ago
TypeScript
61%
EPL-2.0

Huly Platform

Collaboration · Project Management · Team Chat

27,797

Open-source all-in-one workspace that replaces Linear, Jira, Slack, and Notion for product and engineering teams.

View details
90
Repo Health
86
Technical
62
Dependency
Built with
TypeScript 61%
Svelte 34%
Updated 1 weeks ago
TypeScript
90%
MIT

Kaneo

Product Management · Productivity · Project Management

9,250

Lightweight self-hosted project management that gives you kanban boards, GitHub sync, and full team collaboration without the enterprise bloat.

View details
87
Repo Health
81
Technical
70
Dependency
Built with
TypeScript 90%
Updated 1 weeks ago
TypeScript
85%
Apache 2.0

superset

AI Code Assistants · AI Development

14,690

Orchestrate an army of AI coding agents—Claude Code, Codex, Gemini CLI, and more—running simultaneously in isolated git worktrees from a single Electron desktop app.

View details
86
Repo Health
80
Technical
64
Dependency
Built with
TypeScript 85%
Updated 1 weeks ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers