Live data · updated Aug 8, 2026 · 04:01 UTC

The State of Webhooks

A live, privacy-preserving look at real webhook traffic through Webhook Relay — which providers send them, the HTTP clients and languages behind them, and where they come from. Every figure is a share of traffic; aggregate fingerprints only, no payloads, headers or customer data.

Platform + public bin, unioned

Providers

45

identified

HTTP clients

18

fingerprinted

Languages

8

detected

TLS 1.3

87%

of connections

POST

98%

of requests

Top webhook providers

Share of traffic by sending service

  • AWS EventBridge
    39%
  • Juniper Mist
    23%
  • GitHub
    11.2%
  • Adyen
    9.2%
  • Splunk
    7.9%
  • SendGrid
    4.6%
  • WAHA
    2.4%
  • Atlassian
    0.6%
  • Stripe
    0.5%
  • Vesta
    0.4%
  • Svix
    0.3%
  • Bitbucket
    0.2%

Top 12 of 45 identified providers

HTTP clients

Share of traffic by client library or runtime

  • Go
    55.8%
  • Java
    30.5%
  • Python (urllib)
    8.8%
  • Axios
    2.4%
  • OkHttp
    0.7%
  • Node.js
    0.6%
  • Requests
    0.5%
  • Ruby
    0.4%
  • PHP
    0.1%
  • cURL
    0.1%
  • Browser
    <0.1%
  • Deno
    <0.1%

Provider share over time

Top 10 providers + other — each row is one collection interval (adds to 100%)

138 collection intervals · 100% stacked share per window (not lifetime cumulative)

Languages

Share of traffic by inferred language

  • Go
    56.1%
  • Java
    31%
  • Python
    9.3%
  • JavaScript
    3%
  • Ruby
    0.4%
  • PHP
    0.1%
  • C
    0.1%
  • .NET
    <0.1%

How webhooks travel

Transport security and HTTP method

Transport security

  • TLS 1.387.3%
  • TLS 1.212.6%
  • Plaintext0.0%

HTTP method

  • POST98.3%
  • GET1.7%
  • Other0.0%

Content types

Share of traffic by Content-Type header

  • application/json
    98.9%
  • application/x-www-form-urlencoded
    0.7%
  • text/plain
    0.1%
  • multipart/form-data
    <0.1%
  • application/webhook+json
    <0.1%
  • application/xml
    <0.1%
  • application/octet-stream
    <0.1%
  • text/xml
    <0.1%
  • application/vnd.apache.thrift.json
    <0.1%
  • application/cloudevents+json
    <0.1%

Payload size

Share of traffic by size (from the Content-Length header)

  • empty
    1.8%
  • <1 KB
    79.2%
  • 1-10 KB
    13.9%
  • 10-100 KB
    5.1%
  • 100 KB-1 MB
    <0.1%
  • 1-10 MB
    <0.1%
  • >10 MB
    <0.1%

Where webhooks come from

Share of traffic by sender country

  • 🇺🇸 United States
    65.7%
  • 🇮🇪 Ireland
    16.8%
  • 🇬🇧 United Kingdom
    4.9%
  • 🇩🇪 Germany
    4.4%
  • 🇳🇱 Netherlands
    4%
  • 🇮🇹 Italy
    1.1%
  • 🇮🇩 Indonesia
    1.1%
  • 🇮🇳 India
    1%
  • 🇸🇬 Singapore
    0.2%
  • 🇧🇷 Brazil
    0.1%

Top 10 of 100 countries · drag to spin the globe

Where webhooks come from — over time

Top 10 countries + other — each row is one collection interval (adds to 100%)

138 collection intervals · 100% stacked share per window (not lifetime cumulative)

About this data

Figures come from two privacy-preserving sources you can switch between above: the Webhook Relay platform (real customer webhook delivery) and the public, no-signup webhook bin (an open testing endpoint). Each request is fingerprinted into aggregate counters — provider, client family, language, country, TLS version, HTTP method — and nothing else is kept. No payloads, header values, IP addresses or customer identifiers are ever stored, and only shares are shown here.

Snapshots are collected every few hours and this page rebuilds against the newest one, so it tracks live traffic over time. The over-time charts show one 100% share bar per collection interval (roughly every four hours): platform counters are differenced per replica, and bin rollups are differenced across consecutive windows — so a redeploy or window expansion doesn't freeze the mix at lifetime totals. Each row is the top 10 keys plus an Other remainder so it always adds to 100%. The public bin also absorbs a lot of automated and abusive traffic, so its shares skew toward a handful of high-volume senders — switch to Platform for the mix that reflects real customer delivery, and read the rankings as “what we see,” not a market survey.