OneShot

All packsWebhook Durability & ReplaySolve

webhook admin dashboard dev only no auth surface

An ops page needs authentication -- so build a dev-only page instead of authentication

A production webhook-ops dashboard needs real auth, and building that here would duplicate a whole other pack and fail review -- so the UI is dev-only and every real operation is a CLI (D18).

This is one of the things Webhook Durability & Replay already handles. Receive webhooks without losing, duplicating or misordering them when the sender retries.

Buy for $1493 of 3 clean-room builds passed · full refund if it fails on your machine

Is this you?

Shipping a webhook status/replay dashboard that's reachable in production without its own authentication is a real security surface -- delivery contents, dead-letter payloads, and a replay trigger are all things an unauthenticated visitor shouldn't get. Building real authentication just for this one page means re-deriving session handling, roles, and access control that a dedicated auth pack already owns.

Why this one is easy to get wrong

An operator wants to see webhook status somewhere, and a page under /dev or /admin is the obvious way to give them one -- "add a quick auth check" sounds like a small addition to that page, not a decision that duplicates an entire other product's scope and, done badly, introduces its own vulnerability.

What you get instead

D18 makes the one UI surface (/dev/webhooks) dev-only by construction -- notFound() when NODE_ENV === 'production' -- and pushes every real operation into CLIs instead: npm run webhooks:status, webhooks:replay, webhooks:backfill, worker. That gives an operator surface with zero auth surface, on the explicit reasoning that building authentication here would duplicate the multitenant-auth-rbac pack and fail review.

Source: ARCHITECTURE.md D18 — checkable in the pack you receive

How you actually use this

You don’t install a library or wire up an SDK. Your own coding agent builds the code in your project, and you keep it — no runtime dependency on us.

  1. Step 1

    Download and unzip

    You get a folder: the docs that tell an agent what to build, a starting skeleton, and the test suite that decides when it's done.

  2. Step 2

    Open it in Claude Code or Cursor

    Point your coding agent at the folder. Nothing to install, no account with us, no API key.

  3. Step 3

    Paste one prompt

    The pack contains the exact prompt. Paste it as your first message and leave it alone — it works through the build itself, choosing a cheaper or stronger model per task.

  4. Step 4

    Run ./verify.sh

    One command. It prints a pass or fail for every check. Green means the build is done — the same script we ran to produce the receipt on this page.

Typical build: about 40 minutes of your agent working, mostly unattended. Then you integrate the working module into your app the way you would any code you’d written yourself.

Why you can believe this

3 of 3 runs passed

We ran this pack from an empty folder 3 times and published exactly what happened — every check, the model, the token cost, the wall time. Not a testimonial, and not our opinion: the same verify.sh you run yourself. Read the full receipt →

Buy for $14914-day refund if verify.sh fails →

Related problems