Skip to content

Capture & inspect requests

Every endpoint records the requests sent to it as events. This page covers how endpoint URLs work, what you see for each event, and the settings that control capture.

An endpoint URL has three parts:

https://acme-demo.requestify.dev/brave-eager-turing/any/path/you/like?and=query
└─ workspace ─┘ └── endpoint ──┘└── anything after it ──┘
  • Any method is captured: GET, POST, PUT, PATCH, DELETE, OPTIONS and the rest.
  • Any path after the endpoint name is captured and shown on the event, so one endpoint can receive webhooks for several integrations at /stripe, /github and so on.
  • Request bodies are captured for POST, PUT and PATCH. Bodies sent with other methods, such as a GET with a body, aren’t stored.
  • Keep the slash after the endpoint name. …/brave-eager-turing/ is the endpoint; …/brave-eager-turing without the slash isn’t routed to it.

To get an endpoint’s URL, select it on the Requests page and click the copy button next to its name. To add another endpoint, open the Endpoints menu (☰) and choose Create new. New endpoints get a random three-word name.

When mocks are off, Requestify replies to every captured request the same way, so senders that check for a 2xx response are satisfied:

Situation Response
Captured 201 with {"eventId": "…", "message": "ok"} and an X-Requestify-Event-Id header
Unknown or disabled endpoint 404 with {"error": "endpoint not found"}
Auth header missing or wrong (see below) 401 with {"error": "unauthorized"}
Body over 10 MB 413 with {"error": "request body too large"}
Over your plan’s requests-per-minute limit 429

To reply with your own status, headers and body instead, see Mock responses.

Select an event in the list to open it on the right. The header shows the method and path, and the panel lists:

  • Headers, with a button to copy them all.
  • Query Parameters, when there are any, also with a copy button.
  • Body, with its size and a download button.

A captured Stripe-style POST request: headers, query parameters, a formatted JSON body, and the Copy cURL and See Mocks buttons along the bottom.

The body viewer adapts to the content type:

  • JSON is pretty-printed. XML and HTML are indented.
  • Multipart form data is split into its parts. Each part shows its file or field name, a download button and its headers. Open Preview to see an image part, or a text part’s value.
  • Binary content such as PDFs, archives, audio and video shows its type and size, with a Download File button. Images are previewed inline.
  • Compressed bodies sent with Content-Encoding: gzip, deflate or br are shown decompressed.
  • Anything else is shown as plain text.

A multipart upload split into parts, with the image part previewed.

To keep secrets off your screen, the values of sensitive headers are shown as ***MASKED***. This covers Authorization, Proxy-Authorization, Cookie, Set-Cookie, X-API-Key, X-Auth-Token, X-Access-Token, X-CSRF-Token and similar token headers.

Requestify still stores the real values, and replays send them. Copied cURL commands contain the masked placeholder, so put the real value back before running one.

Copy cURL at the bottom of the event panel copies a curl command that repeats the request against the same endpoint, with the same method, path, headers and body. It’s a quick way to resend a webhook from your terminal or tweak it before sending.

The Events menu (☰) above the list has three settings:

  • Auto-scroll to latest keeps the newest event in view as requests arrive.
  • Hide OPTIONS hides CORS preflight requests from the list. It’s on by default.
  • Clear all events deletes every event on the selected endpoint.

The Events menu open, showing Auto-scroll to latest, Hide OPTIONS and Clear all events.

To delete a single event, select it and click the trash icon at the end of its row.

Events are kept for a period that depends on your plan, then deleted automatically. See pricing for the current retention.

The Endpoints menu (☰) above the endpoint card has:

  • Create new adds an endpoint with a random name and selects it.
  • Enabled turns the endpoint on or off. A disabled endpoint answers 404 and captures nothing. Its existing events and settings are kept, and switching it back on restores it.
  • Delete removes the endpoint along with all of its events. If you delete your last endpoint, a new one is created for you.

The Endpoints menu open, showing Create new, the Enabled switch and Delete.

The number of endpoints you can have depends on your plan.

By default anyone who knows an endpoint’s URL can send to it. To accept only requests that carry a secret, switch on Auth on the endpoint card:

  1. Turn on the Auth switch. Requestify fills in a header name, x-requestify-auth, and a random value.
  2. Click the arrow next to the switch to see or change the Header name and Expected value. Both have copy buttons.
  3. Configure your sender to include that header on every request.

The Auth switch turned on, with its popover showing the Header name and Expected value fields.

Requests without the header, or with a different value, get 401 and aren’t captured. CORS preflight (OPTIONS) requests are let through, because browsers don’t attach custom headers to them. Send test request includes the header automatically.

  • Proxy & replay: forward requests to your own server and resend them later.
  • Mock responses: reply with a status, headers and body you define.