Sparrow is an open-source webhook delivery server: at-least-once delivery, retries with error classification, signed deliveries, and OpenTelemetry tracing. One Go binary. One PostgreSQL database.
Events persist in PostgreSQL before fan-out begins. At-least-once delivery with exponential backoff, manual retry, and full event replay.
How it worksTen error categories separate what retries (5xx, timeouts, 429s, refused connections) from dead ends (4xx, DNS, TLS). You always know why a delivery failed.
Error referenceEvery delivery signed per Standard Webhooks — HMAC-SHA256 by default, Ed25519 per webhook. Secrets envelope-encrypted at rest with AES-256-GCM. SSRF protection blocks private and metadata IPs.
Webhook APIOpenTelemetry traces propagate through every queue job; structured logs and metrics export via OTLP. The embedded dashboard shows delivery logs and per-webhook health, and interactive API docs render live at /docs.
Hand each consumer a scoped, expiring link to a self-service portal: they register their own endpoints, browse the event catalog, and inspect and retry their own delivery logs — no admin key, no access to anyone else's data.
Consumer portalNo Redis, no Kafka, no sidecar queue. A single Go binary plus PostgreSQL; migrations run automatically on startup. The UI ships embedded in the binary.
InstallMIT-licensed and built in the open. The REST API is described by a committed OpenAPI 3.1 spec, so you can generate a client in any language.
Star on GitHubPush an event with an idempotency key and Sparrow validates it, persists it, and fans out to every matching subscription. Duplicate pushes are detected and returned as such.
Each delivery arrives signed per Standard Webhooks — HMAC-SHA256 with a shared secret by default, or switch a webhook to Ed25519 to verify with a public key instead.
$ curl -X POST "http://localhost:8080/v1/consumers/payments/events?event=invoice.created" \ -H "Content-Type: application/json" \ -H "X-API-Key: sk_live_..." \ -d '{ "payload": '{"id":"inv_01","amount":4999}', "idempotency_key": "idem_abc123" }' // 201 Created { "event_id": "evt_7f3a...", "duplicate": false } River workers drive the pipeline over the same database that stores your events. Fan-out matches subscriptions and applies per-subscription Go template transforms; delivery POSTs with signatures and per-webhook rate limits.
When a delivery fails, the error is classified before anything else happens. Retryable failures back off exponentially; permanent ones stop immediately and mark webhook health.
How it worksCompanion tools built entirely on the public REST API and signed-webhook contract. The core stays one small server; every satellite — including yours — inherits retries, signing, and the delivery audit trail. How satellites work →
Push events, tail deliveries, receive webhooks locally, and debug transform templates from your terminal.
sparrow CLISlack, Discord, PagerDuty, ntfy, ClickHouse, Twilio, SendGrid — adapters as config, applied with sparrow use. No glue service.
Compose and preview any recipe in the browser — pick a destination, edit the payload or message, watch the live preview, then copy the exact sparrow use command. No install needed.
Cron schedules plus Stripe and GitHub webhooks, verified and re-published as Sparrow events by sparrow-sources.
Signed deliveries forwarded out of HTTP land — SMTP email, S3/MinIO archives, and OTLP log export via sparrow-sinks.
Directional snapshot against the main alternatives — vendors change packaging often, so verify details against their docs. Full feature comparison →
| Sparrow | Svix | Convoy | Hookdeck | DIY | |
|---|---|---|---|---|---|
| Fully open source (MIT) | Yes | Partial | No (Elastic 2.0) | Partial | Yes |
| Core infrastructure | PostgreSQL only | PostgreSQL + Redis | PostgreSQL + Redis | SaaS | Varies |
| Webhook signing | HMAC-SHA256 + Ed25519 | HMAC-SHA256 | HMAC-SHA256 | HMAC-SHA256 | Manual |
| Secrets at rest | Envelope encryption, per-record DEKs | Encrypted at rest | Deployment-dependent | Vendor-managed | Manual |
| Payload transforms | Go templates, cached, no JS runtime | Plan-dependent | JavaScript | JavaScript | Manual |
| Prebuilt integrations | Recipes: Slack, Discord, PagerDuty, ntfy, ClickHouse | Limited | Limited | Yes | Manual |
| Self-monitoring alerts | System events + email alerts | Operational webhooks | Alert configs | Issue alerts | Manual |
| Tracing & metrics | OpenTelemetry end-to-end | Logging | Prometheus | Dashboard | Manual |
| Consumer portal | Yes — self-hosted, token-scoped | Yes | Yes | Yes | No |
Download the Compose file and bring it up. No clone, no secrets, no .env -- PostgreSQL included, migrations run automatically on first boot.
$ curl -O https://raw.githubusercontent.com/sarathsp06/sparrow/main/deploy/docker-compose.yml $ docker compose up -d Creating sparrow-postgres-1 ... done Creating sparrow-sparrow-1 ... done $ open http://localhost:8080