{"id":"fa7a9498-5dcd-414f-ad5c-8a91db380cfd","entityType":"agent","slug":"clawhub-7schmiede-hookaido","name":"Hookaido Webhook Integration","canonicalUrl":"https://www.xpersona.co/agent/clawhub-7schmiede-hookaido","canonicalPath":"/agent/clawhub-7schmiede-hookaido","generatedAt":"2026-10-10T02:15:59.948Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T20:12:46.942Z","emptyReason":null},"description":"Webhook infrastructure for receiving, queuing, and delivering webhooks. Operate Hookaido webhook ingress, durable webhook queue (SQLite/Postgres), webhook de...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s172ytmvxmznx2s25dx1dnqs4583fcr3:hookaido","sourceUrl":"https://clawhub.ai/7schmiede/hookaido","homepage":"https://clawhub.ai/7schmiede/skills/hookaido","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/7schmiede/hookaido","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/7schmiede/skills/hookaido","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":59,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Hookaido Webhook Integration technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T20:12:46.942Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T20:12:46.942Z","emptyReason":null},"stars":null,"forks":null,"downloads":2038,"packageName":null,"latestVersion":"2.6.0","tractionLabel":"2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T20:12:46.942Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T20:12:46.942Z","lastCrawledAt":"2026-10-09T20:12:46.942Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T20:12:46.942Z","lastVerifiedAt":null,"highlights":[{"version":"2.6.0","createdAt":"2026-04-20T22:20:18.274Z","changelog":"- Version bump to 2.6.0 with updated binaries and install sources. - Added a LICENSE file. - Support for new webhook providers and delivery types reflected in documentation. - Expanded install matrix for more platforms with version 2.6.0 artifacts. - Documentation updates to reference v2.6.0 features and instructions.","fileCount":9,"zipByteSize":15396},{"version":"2.2.4","createdAt":"2026-04-15T11:11:18.837Z","changelog":"- Added .clawhubignore and LICENSE files to the repository. - Introduced scripts/publish.sh for automation or publishing tasks. - Updated install instructions and binaries to target Hookaido v2.2.2. - Minor version bump to 2.2.4 for the skill descriptor.","fileCount":8,"zipByteSize":12766},{"version":"2.2.3","createdAt":"2026-03-30T16:25:43.708Z","changelog":"- Updated default Hookaido version references from v2.2.0 to v2.2.1 in install workflows and documentation. - Adjusted pinned install script, binary download URLs, and Go module install steps for v2.2.1. - SKILL.md and related docs now reflect usage and recommendations for Hookaido v2.2.1. - No functional logic changes; update is focused on maintaining compatibility with upstream v2.2.1 release.","fileCount":7,"zipByteSize":11789},{"version":"2.2.2","createdAt":"2026-03-28T14:11:54.652Z","changelog":"- Updated the skill version to 2.2.2. - Clarified and shortened the description for better readability and focus on core Hookaido webhook functionality. - Improved documentation by emphasizing webhook infrastructure, queue backends, delivery modes, and CLI usage. - No functional or interface changes—documentation only.","fileCount":7,"zipByteSize":11715},{"version":"2.2.1","createdAt":"2026-03-28T14:09:56.346Z","changelog":"Version 2.2.1 - Updated install methods and binary URLs to use Hookaido v2.2.0. - Added and documented subprocess delivery support (deliver exec). - Specified required environment variables (e.g., HOOKAIDO_PULL_TOKEN, HOOKAIDO_INGRESS_SECRET). - Improved docs/playbooks for provider-compatible HMAC authentication (GitHub/Gitea). - Minor workflow and metadata clarifications to reflect new features and requirements.","fileCount":7,"zipByteSize":11711},{"version":"2.0.1","createdAt":"2026-03-10T16:53:39.049Z","changelog":"Update Name and Description","fileCount":7,"zipByteSize":10409},{"version":"2.0.0","createdAt":"2026-03-09T21:36:53.815Z","changelog":"Hookaido v2.0.0 is a major release with new modular backend and verification features. - Added support for modular queue backends (`sqlite`, `memory`, `postgres`) - Introduced release signature and checksum verification via `verify-release` - Playbooks and validation flows updated to cover new backend options and stricter secret checking - New install sources and instructions, including source-based install and updated artifact URLs for v2.0.0 - Documentation and workflow steps expanded for batch pull/ack and Postgres queue scenarios","fileCount":7,"zipByteSize":10269},{"version":"1.5.0","createdAt":"2026-02-15T01:02:50.248Z","changelog":"- Updated hookaido version to 1.5.0 for all platform installers. - Workflow and install instructions updated to reference v1.5.0. - Description clarified to include \"webhook/webhooks ingress and delivery.\" - No functional or procedural changes beyond version updates.","fileCount":5,"zipByteSize":7393}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s172ytmvxmznx2s25dx1dnqs4583fcr3:hookaido","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s172ytmvxmznx2s25dx1dnqs4583fcr3:hookaido` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/7schmiede/hookaido before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-7schmiede-hookaido/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-7schmiede-hookaido/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-7schmiede-hookaido/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-7schmiede-hookaido/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-7schmiede-hookaido/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-7schmiede-hookaido/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T02:15:59.946Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-7schmiede-hookaido/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-7schmiede-hookaido/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-7schmiede-hookaido/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-7schmiede-hookaido/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T20:12:46.942Z","emptyReason":null},"readme":"Skill: Hookaido Webhook Integration\n\nOwner: 7schmiede\n\nSummary: Webhook infrastructure for receiving, queuing, and delivering webhooks. Operate Hookaido webhook ingress, durable webhook queue (SQLite/Postgres), webhook de...\n\nTags: latest:2.6.0\n\nVersion history:\n\nv2.6.0 | 2026-04-20T22:20:18.274Z | user\n\n- Version bump to 2.6.0 with updated binaries and install sources.\n- Added a LICENSE file.\n- Support for new webhook providers and delivery types reflected in documentation.\n- Expanded install matrix for more platforms with version 2.6.0 artifacts.\n- Documentation updates to reference v2.6.0 features and instructions.\n\nv2.2.4 | 2026-04-15T11:11:18.837Z | user\n\n- Added .clawhubignore and LICENSE files to the repository.\n- Introduced scripts/publish.sh for automation or publishing tasks.\n- Updated install instructions and binaries to target Hookaido v2.2.2.\n- Minor version bump to 2.2.4 for the skill descriptor.\n\nv2.2.3 | 2026-03-30T16:25:43.708Z | auto\n\n- Updated default Hookaido version references from v2.2.0 to v2.2.1 in install workflows and documentation.\n- Adjusted pinned install script, binary download URLs, and Go module install steps for v2.2.1.\n- SKILL.md and related docs now reflect usage and recommendations for Hookaido v2.2.1.\n- No functional logic changes; update is focused on maintaining compatibility with upstream v2.2.1 release.\n\nv2.2.2 | 2026-03-28T14:11:54.652Z | auto\n\n- Updated the skill version to 2.2.2.\n- Clarified and shortened the description for better readability and focus on core Hookaido webhook functionality.\n- Improved documentation by emphasizing webhook infrastructure, queue backends, delivery modes, and CLI usage.\n- No functional or interface changes—documentation only.\n\nv2.2.1 | 2026-03-28T14:09:56.346Z | auto\n\nVersion 2.2.1\n\n- Updated install methods and binary URLs to use Hookaido v2.2.0.\n- Added and documented subprocess delivery support (deliver exec).\n- Specified required environment variables (e.g., HOOKAIDO_PULL_TOKEN, HOOKAIDO_INGRESS_SECRET).\n- Improved docs/playbooks for provider-compatible HMAC authentication (GitHub/Gitea).\n- Minor workflow and metadata clarifications to reflect new features and requirements.\n\nv2.0.1 | 2026-03-10T16:53:39.049Z | user\n\nUpdate Name and Description\n\nv2.0.0 | 2026-03-09T21:36:53.815Z | user\n\nHookaido v2.0.0 is a major release with new modular backend and verification features.\n\n- Added support for modular queue backends (`sqlite`, `memory`, `postgres`)\n- Introduced release signature and checksum verification via `verify-release`\n- Playbooks and validation flows updated to cover new backend options and stricter secret checking\n- New install sources and instructions, including source-based install and updated artifact URLs for v2.0.0\n- Documentation and workflow steps expanded for batch pull/ack and Postgres queue scenarios\n\nv1.5.0 | 2026-02-15T01:02:50.248Z | user\n\n- Updated hookaido version to 1.5.0 for all platform installers.\n- Workflow and install instructions updated to reference v1.5.0.\n- Description clarified to include \"webhook/webhooks ingress and delivery.\"\n- No functional or procedural changes beyond version updates.\n\nv1.4.0 | 2026-02-14T20:02:03.964Z | user\n\nSummary: Adds gRPC-pull support, updates install/download targets, and revises operation/validation flows.\n\n- Added support for gRPC pull-worker listeners and gRPC pull operations.\n- Updated install/download URLs to reference hookaido v1.4.0 binaries.\n- Revised workflow and playbooks to include gRPC in topologies and validation steps.\n- Clarified pull API models and sample configurations with optional gRPC listener.\n- Improved validation checklist to cover gRPC-pull and related consumer actions.\n\nv1.3.0 | 2026-02-14T01:58:02.821Z | user\n\nhookaido v1.3.0 introduces improved runtime install guidance, especially supporting Docker environments.\n\n- Updated install links to reference v1.3 binaries for all platforms.\n- Expanded workflow section to clearly document host and Docker-based install options, including SHA256 verification.\n- Added instructions for sandbox/Docker image and `setupCommand` usage to support new execution environments.\n- Maintained host install as fallback and for requirements check.\n- No breaking changes to configuration or runtime operation.\n\nv1.2.0 | 2026-02-13T22:47:53.991Z | user\n\n- Added install instructions and automated installation support for the hookaido CLI via scripts/install_hookaido.sh.\n- Updated SKILL.md to include OpenClaw install metadata and provide step-by-step installation guidance.\n- Users can now ensure hookaido is on PATH either through OpenClaw install actions or the provided shell script.\n\nv1.0.0 | 2026-02-13T22:22:00.561Z | user\n\nInitial release of the Hookaido skill.\n\n- Provides guidance for creating, reviewing, and operating Hookaido webhook queue setups.\n- Includes workflows for config validation, running, health checks, and queue/DLQ triage.\n- Offers step-by-step playbooks for configuring ingress, pull, and push delivery modes.\n- Documents safe operation, mutation, and production hardening practices.\n- Emphasizes conservative changes, validation, and secure secret handling.\n\nArchive index:\n\nArchive v2.6.0: 9 files, 15396 bytes\n\nFiles: agents/openai.yaml (262b), README.md (1060b), references/operations.md (9516b), RELEASE_NOTES.md (4477b), scripts/install_hookaido.sh (4705b), scripts/publish.sh (942b), skill-card.md (2466b), SKILL.md (13071b), _meta.json (127b)\n\nFile v2.6.0:SKILL.md\n\n---\nname: hookaido\nversion: \"2.6.0\"\ndescription: >-\n  Webhook infrastructure for receiving, queuing, and delivering webhooks.\n  Operate Hookaido webhook ingress, durable webhook queue (SQLite/Postgres),\n  webhook delivery (HTTP push, subprocess exec, pull API, SSE streaming),\n  webhook signature verification (HMAC, GitHub, Gitea, Stripe, Cituro),\n  dead-letter queue, and webhook retry policies. Use when tasks involve webhook\n  endpoint configuration (Hookaidofile), webhook queue backends (sqlite, memory,\n  postgres), hookaido CLI (run, config fmt, config validate, mcp serve),\n  webhook consumption (dequeue/ack/nack/extend) over HTTP, SSE, or gRPC,\n  subprocess webhook handlers (deliver exec), webhook provider HMAC\n  (GitHub/Gitea/Stripe/Cituro), Admin API webhook backlog/DLQ triage, or\n  production webhook hardening.\nmetadata:\n  openclaw:\n    homepage: https://github.com/7schmiede/claw-skill-hookaido\n    emoji: \"\\U0001FA9D\"\n    primaryEnv: HOOKAIDO_PULL_TOKEN\n    requires:\n      bins:\n        - hookaido\n      env:\n        - HOOKAIDO_PULL_TOKEN\n        - HOOKAIDO_INGRESS_SECRET\n    install:\n      - id: go-install\n        kind: go\n        package: github.com/nuetzliches/hookaido/cmd/hookaido@v2.6.0\n        bins:\n          - hookaido\n      - id: download-darwin-amd64\n        kind: download\n        os:\n          - darwin\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.6.0/hookaido_v2.6.0_darwin_amd64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.6.0 (macOS amd64)\n      - id: download-darwin-arm64\n        kind: download\n        os:\n          - darwin\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.6.0/hookaido_v2.6.0_darwin_arm64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.6.0 (macOS arm64)\n      - id: download-linux-amd64\n        kind: download\n        os:\n          - linux\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.6.0/hookaido_v2.6.0_linux_amd64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.6.0 (Linux amd64)\n      - id: download-linux-arm64\n        kind: download\n        os:\n          - linux\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.6.0/hookaido_v2.6.0_linux_arm64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.6.0 (Linux arm64)\n      - id: download-windows-amd64\n        kind: download\n        os:\n          - win32\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.6.0/hookaido_v2.6.0_windows_amd64.zip\n        archive: zip\n        extract: true\n        targetDir: ~/.openclaw/tools/hookaido\n        bins:\n          - hookaido\n        label: Download hookaido v2.6.0 (Windows amd64)\n      - id: download-windows-arm64\n        kind: download\n        os:\n          - win32\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.6.0/hookaido_v2.6.0_windows_arm64.zip\n        archive: zip\n        extract: true\n        targetDir: ~/.openclaw/tools/hookaido\n        bins:\n          - hookaido\n        label: Download hookaido v2.6.0 (Windows arm64)\n---\n\n# Hookaido\n\n## Overview\n\nImplement and troubleshoot Hookaido with a config-first workflow: edit `Hookaidofile`, validate, run, exercise ingress/pull/exec flows, then diagnose queue health and DLQ behavior.\nTreat Hookaido v2.6.0's modular architecture as additive in this skill: keep the existing workflow intact by default, and opt into modules such as `postgres`, gRPC workers, subprocess delivery (`deliver exec`), or release verification only when they materially help the task.\nUse conservative, reversible changes and validate before runtime operations.\n\n## Workflow\n\n1. Confirm target topology: inbound+pull (HTTP or gRPC), push outbound, subprocess exec, or internal queue, plus the queue backend (`sqlite`, `memory`, or `postgres`).\n2. Choose runtime mode and ensure `hookaido` exists where tools execute.\n   - Host-binary mode: use the install action from `metadata.openclaw.install`.\n   - Host fallback: run `bash {baseDir}/scripts/install_hookaido.sh` (pinned `v2.6.0`, SHA256-verified).\n   - Public repo/source mode: use the public upstream repo `github.com/nuetzliches/hookaido` via `go install github.com/nuetzliches/hookaido/cmd/hookaido@v2.6.0` when a source-based install is preferred.\n   - Docker-sandbox mode: use a sandbox image that already includes `hookaido` (preferred), or install inside sandbox via `agents.defaults.sandbox.docker.setupCommand`.\n   - Keep host install actions available as fallback and to satisfy `metadata.openclaw.requires.bins`.\n3. Inspect and update `Hookaidofile` minimally.\n4. Run format and validation before starting or reloading:\n   - `hookaido config fmt --config ./Hookaidofile`\n   - `hookaido config validate --config ./Hookaidofile`\n   - `hookaido config validate --config ./Hookaidofile --strict-secrets` when secret refs or Vault-backed config are involved.\n5. Start runtime and verify health:\n   - `hookaido run --config ./Hookaidofile --db ./.data/hookaido.db`\n   - `hookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"` when `queue postgres` is selected.\n   - `curl http://127.0.0.1:2019/healthz?details=1`\n6. Validate end-to-end behavior:\n   - ingress request accepted and queued\n   - consumer `dequeue`/`ack`/`nack`/`extend` path works (HTTP pull, batch `ack`/`nack`, plus gRPC pull when enabled)\n7. For incidents, inspect backlog and DLQ first, then mutate.\n\n## Task Playbooks\n\n### Configure Ingress and Pull Consumption\n\n1. Define a route with explicit auth and pull path (HTTP pull, optional gRPC pull worker listener).\n2. Keep secrets in env/file refs, never inline.\n3. Verify route and global pull auth are consistent.\n4. Test with a real webhook payload and a dequeue/ack cycle, using batch `ack`/`nack` when worker throughput matters.\n\nPrefer this baseline:\n\n```hcl\ningress {\n  listen :8080\n}\n\npull_api {\n  listen :9443\n  grpc_listen :9943 # optional gRPC pull-worker listener\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\n  pull { path /pull/github }\n}\n```\n\n### Configure Push Delivery\n\n1. Use push delivery only when inbound connectivity to the service is acceptable.\n2. Set timeout and retry policy explicitly.\n3. Validate downstream idempotency since delivery is at-least-once.\n\n```hcl\n/webhooks/stripe {\n  auth hmac env:STRIPE_SIGNING_SECRET\n  deliver \"https://billing.internal/stripe\" {\n    retry exponential max 8 base 2s cap 2m jitter 0.2\n    timeout 10s\n  }\n}\n```\n\n### Configure Subprocess Delivery (`deliver exec`)\n\n1. Use exec delivery when the target is a local script or binary, not an HTTP service.\n2. Payload is piped to stdin; metadata arrives as env vars (`HOOKAIDO_ROUTE`, `HOOKAIDO_EVENT_ID`, `HOOKAIDO_ATTEMPT`, etc.).\n3. Exit code determines retry behavior: `0` = ack, `1-125` = retry, `126`/`127` = immediate DLQ.\n4. `sign` directives are not supported with exec (compile error).\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  deliver exec \"/opt/hooks/deploy.sh\" {\n    timeout 30s\n    retry exponential max 3 base 1s cap 30s jitter 0.2\n    env DEPLOY_ENV production\n    env NOTIFY_URL {env.SLACK_WEBHOOK_URL}\n  }\n}\n```\n\n### Configure Provider-Compatible HMAC\n\n1. Use `provider github`, `provider gitea`, `provider stripe`, or `provider cituro` for webhook providers with their own signature format.\n2. Provider mode disables timestamp/nonce replay protection (providers do not send those headers).\n3. `signature_header`, `timestamp_header`, `nonce_header`, and `tolerance` are forbidden in provider mode (compile error).\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  pull { path /pull/github }\n}\n\n/webhooks/gitea {\n  auth hmac {\n    provider gitea\n    secret env:GITEA_WEBHOOK_SECRET\n  }\n  pull { path /pull/gitea }\n}\n\n/webhooks/stripe {\n  auth hmac {\n    provider stripe\n    secret env:STRIPE_SIGNING_SECRET\n  }\n  pull { path /pull/stripe }\n}\n\n/webhooks/cituro {\n  auth hmac {\n    provider cituro\n    secret env:CITURO_WEBHOOK_SECRET\n  }\n  pull { path /pull/cituro }\n}\n```\n\n### Use SSE Streaming (v2.5.3+)\n\n1. SSE replaces polling for real-time webhook delivery — use `GET {pull.path}/stream` instead of repeated `POST .../dequeue`.\n2. ACK/NACK operations use the same existing POST endpoints; no protocol change.\n3. Multiple concurrent SSE connections act as competing consumers.\n4. Configure keepalive interval (`keepalive`) and max connection duration (`max_duration`) in the route's `pull` block.\n\n```bash\n# Connect SSE stream (persistent, server pushes events)\ncurl -sS -N \"http://localhost:9443/pull/github/stream\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\"\n\n# ACK received event\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\"}'\n```\n\n### Configure Queue Backends\n\n1. Default to `sqlite` unless the task explicitly needs ephemeral dev mode or shared Postgres storage.\n2. Treat `memory` and `postgres` as additive v2 modules, not replacements for existing sqlite workflows.\n3. When using `postgres`, document the DSN source and validate health plus backlog endpoints after startup.\n\nPrefer these patterns:\n\n```hcl\nqueue sqlite\n\nqueue memory\n\nqueue postgres\n```\n\n### Operate Queue and DLQ\n\n1. Start with health details and backlog endpoints.\n2. Inspect DLQ before requeue or delete.\n3. If requeueing many items, explain expected impact and rollback path.\n4. Require clear operator reason strings for mutating admin calls.\n\nUse:\n\n- `GET /healthz?details=1`\n- `GET /backlog/trends`\n- `GET /dlq`\n- `POST /dlq/requeue`\n- `POST /dlq/delete`\n\n### Use MCP Mode for AI Operations\n\n1. Default to `--role read` for diagnostics.\n2. Enable mutations only with explicit operator intent:\n   - `--enable-mutations --role operate --principal <identity>`\n3. Enable runtime control only for admin workflows:\n   - `--enable-runtime-control --role admin --pid-file <path>`\n4. Include `reason` for mutation calls and keep it specific.\n\n#### Register as Claude Code MCP Plugin\n\nAdd to `.claude/settings.json` (or `~/.claude/settings.json` for global use):\n\n```json\n{\n  \"mcpServers\": {\n    \"hookaido\": {\n      \"command\": \"hookaido\",\n      \"args\": [\n        \"mcp\", \"serve\",\n        \"--config\", \"./Hookaidofile\",\n        \"--db\", \"./.data/hookaido.db\",\n        \"--role\", \"read\"\n      ]\n    }\n  }\n}\n```\n\nFor operate role (queue mutations):\n\n```json\n{\n  \"mcpServers\": {\n    \"hookaido\": {\n      \"command\": \"hookaido\",\n      \"args\": [\n        \"mcp\", \"serve\",\n        \"--config\", \"./Hookaidofile\",\n        \"--db\", \"./.data/hookaido.db\",\n        \"--enable-mutations\",\n        \"--role\", \"operate\",\n        \"--principal\", \"claude\"\n      ]\n    }\n  }\n}\n```\n\nThe MCP server exposes structured tools directly — no shell output parsing. Claude Code discovers available tools at startup and uses them with typed parameters.\n\n### Verify Public Releases\n\n1. Prefer official release assets from the public Hookaido repo.\n2. When supply-chain assurance matters, validate checksums, signature material, and provenance before rollout.\n3. Keep verification optional by default so existing skill flows do not become heavier unless the task requires it.\n\nUse:\n\n- `hookaido verify-release --checksums ./hookaido_v2.6.0_checksums.txt --require-provenance`\n\n## Validation Checklist\n\n- `hookaido config validate` returns success before runtime start/reload.\n- `hookaido config validate --strict-secrets` is used when secret refs, Vault, or public-release rollout validation matters.\n- Health endpoint is reachable and reports expected queue/backend state.\n- Pull consumer can `dequeue`, `ack`, `nack`, and `extend` with valid token (HTTP, SSE, and optional gRPC transport), including batch `ack`/`nack` when enabled.\n- For push mode, retry/timeout behavior is explicitly configured.\n- For exec mode, handler script is executable, reads stdin, and uses exit codes correctly (0=ack, non-zero=retry, 126/127=DLQ).\n- For `queue postgres`, runtime is started with `--postgres-dsn` or `HOOKAIDO_POSTGRES_DSN`.\n- Any DLQ mutation is scoped, justified, and logged.\n\n## Safety Rules\n\n- Do not disable auth to \"make tests pass.\"\n- Do not suggest direct mutations before read-only diagnostics.\n- Treat queue operations as at-least-once; require idempotent handlers.\n- Keep secrets in `env:` or `file:` refs.\n\n## References\n\n- Read `references/operations.md` for command snippets and API payload templates.\n\nFile v2.6.0:README.md\n\n# hookaido\n\nPublic OpenClaw skill for [Hookaido](https://github.com/nuetzliches/hookaido) — webhook infrastructure that just works.\n\nRepository link for skill distribution:\n\n- `https://github.com/7schmiede/claw-skill-hookaido`\n\nUpstream Hookaido project:\n\n- `https://github.com/nuetzliches/hookaido`\n\nThis skill is pinned to Hookaido `v2.6.0` and keeps existing inbound/outbound/pull workflows as the default path.\nNew capabilities such as `deliver exec` (subprocess delivery), provider-compatible HMAC (GitHub/Gitea/Stripe/Cituro), SSE streaming (`{pull.path}/stream`), `queue postgres`, gRPC pull workers, batch `ack`/`nack`, and release verification are documented as additive modules so existing usage does not receive breaking changes by default.\n\nMain files:\n\n- `SKILL.md` for skill metadata and operating guidance\n- `references/operations.md` for install, runtime, and API command examples\n- `scripts/install_hookaido.sh` for pinned release-binary installation with SHA256 verification\n- `RELEASE_NOTES.md` for the current public skill release summary\n\nFile v2.6.0:_meta.json\n\n{\n  \"ownerId\": \"kn70n9zjjpmw2dg19a8n5w8bm1813vkf\",\n  \"slug\": \"hookaido\",\n  \"version\": \"2.6.0\",\n  \"publishedAt\": 1776723618274\n}\n\nFile v2.6.0:references/operations.md\n\n# Hookaido Operations Reference\n\nUse this file for concrete command syntax and request payloads.\n\n## Install Hookaido\n\nOpenClaw supports two runtime variants.\n\nPublic repositories:\n\n- Upstream project: `https://github.com/nuetzliches/hookaido`\n- Public skill repo: `https://github.com/7schmiede/claw-skill-hookaido`\n\n### Variant A: Host Binary (Gateway/Host)\n\n- Use one of the skill installer actions from `metadata.openclaw.install` (platform + architecture specific download).\n- Choose the artifact that matches your host architecture (`amd64` or `arm64`).\n- The OpenClaw download URLs are pinned to Hookaido `v2.6.0`.\n- macOS/Linux installers extract to `~/.local/bin` (with `stripComponents: 1`).\n- Windows installers extract to `~/.openclaw/tools/hookaido`.\n\nDirect CLI fallback:\n\n```bash\ngo install github.com/nuetzliches/hookaido/cmd/hookaido@v2.6.0\n```\n\nRelease-binary fallback from this skill folder:\n\n```bash\nbash {baseDir}/scripts/install_hookaido.sh\n```\n\nThe fallback installer is hardened:\n\n- Defaults to pinned `v2.6.0` (no dynamic `latest` lookup).\n- Verifies SHA256 of the downloaded release artifact before extraction/install.\n\nOptional pins/overrides for the installer script:\n\n```bash\n# Default pinned install, custom location\nHOOKAIDO_INSTALL_DIR=\"$HOME/bin\" bash {baseDir}/scripts/install_hookaido.sh\n\n# Non-default release requires explicit checksum\nHOOKAIDO_VERSION=v2.0.1 \\\nHOOKAIDO_SHA256=\"<artifact-sha256>\" \\\nbash {baseDir}/scripts/install_hookaido.sh\n```\n\n### Variant B: Docker Sandbox\n\n- OpenClaw supports Docker sandbox mode via `sandboxing.enabled: true` and `sandboxing.type: docker`.\n- Preferred: provide a custom sandbox image with `hookaido` preinstalled, and pin the image by immutable digest.\n- Optional: use `agents.defaults.sandbox.docker.setupCommand` to install `hookaido` inside the container at startup.\n- Keep `metadata.openclaw.install` as fallback and for `metadata.openclaw.requires.bins` checks on the host.\n\n## Core CLI Commands\n\n```bash\n# Validate and format config\nhookaido config fmt --config ./Hookaidofile\nhookaido config validate --config ./Hookaidofile\nhookaido config validate --config ./Hookaidofile --strict-secrets\n\n# Start runtime\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db\n\n# Start runtime with Postgres queue backend\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\n\n# Start runtime with live config watch\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db --watch\n\n# Start MCP server (read-only)\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\n\n# Verify a public release bundle before rollout\nhookaido verify-release \\\n  --checksums ./hookaido_v2.6.0_checksums.txt \\\n  --public-key ./hookaido_v2.6.0_checksums.txt.pub.pem \\\n  --require-provenance\n```\n\n## Minimal Pull-Mode Config\n\n```hcl\ningress {\n  listen :8080\n}\n\npull_api {\n  listen :9443\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\n  pull { path /pull/github }\n}\n```\n\n## Exec Delivery Config (v2.2.0+)\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  deliver exec \"/opt/hooks/deploy.sh\" {\n    timeout 30s\n    retry exponential max 3 base 1s cap 30s jitter 0.2\n    env DEPLOY_ENV production\n  }\n}\n```\n\nExit codes: `0` = ack, `75`/`1-125` = retry, `126`/`127` = immediate DLQ.\nMetadata env vars: `HOOKAIDO_ROUTE`, `HOOKAIDO_EVENT_ID`, `HOOKAIDO_CONTENT_TYPE`, `HOOKAIDO_ATTEMPT`, `HOOKAIDO_HEADER_*`.\n\n## Provider-Compatible HMAC Config (v2.2.0+)\n\n```hcl\n# GitHub\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  pull { path /pull/github }\n}\n\n# Gitea / Forgejo\n/webhooks/gitea {\n  auth hmac {\n    provider gitea\n    secret env:GITEA_WEBHOOK_SECRET\n  }\n  pull { path /pull/gitea }\n}\n\n# Stripe (v2.6.0+)\n/webhooks/stripe {\n  auth hmac {\n    provider stripe\n    secret env:STRIPE_SIGNING_SECRET\n  }\n  pull { path /pull/stripe }\n}\n\n# Cituro (v2.6.0+)\n/webhooks/cituro {\n  auth hmac {\n    provider cituro\n    secret env:CITURO_WEBHOOK_SECRET\n  }\n  pull { path /pull/cituro }\n}\n```\n\n## Pull API Calls\n\nAssume base URL `http://localhost:9443/pull/github` and token in `HOOKAIDO_PULL_TOKEN`.\n\n```bash\n# Dequeue\ncurl -sS -X POST \"http://localhost:9443/pull/github/dequeue\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"batch\":10,\"lease_ttl\":\"30s\",\"max_wait\":\"5s\"}'\n\n# Ack\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\"}'\n\n# Batch ack (v2.2.0+)\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_ids\":[\"lease_a\",\"lease_b\"]}'\n\n# Nack (requeue with delay)\ncurl -sS -X POST \"http://localhost:9443/pull/github/nack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\",\"delay\":\"5s\",\"dead\":false}'\n\n# Extend lease\ncurl -sS -X POST \"http://localhost:9443/pull/github/extend\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\",\"lease_ttl\":\"30s\"}'\n\n# Batch nack (v2.2.0+)\ncurl -sS -X POST \"http://localhost:9443/pull/github/nack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_ids\":[\"lease_a\",\"lease_b\"],\"delay\":\"5s\",\"dead\":false}'\n```\n\n## Optional gRPC Pull-Worker Mode (`v1.4.0+`)\n\nEnable gRPC pull-worker transport alongside HTTP pull:\n\n```hcl\npull_api {\n  listen :9443\n  grpc_listen :9943\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  pull { path /pull/github }\n}\n```\n\nUse gRPC workers with the same lease semantics and operation parity as Pull HTTP:\n\n- `Dequeue` -> `POST {endpoint}/dequeue`\n- `Ack` -> `POST {endpoint}/ack`\n- `Nack` -> `POST {endpoint}/nack`\n- `Extend` -> `POST {endpoint}/extend`\n\nNotes:\n\n- Worker gRPC reuses pull token auth and pull endpoint routing.\n- Keep `grpc_listen` on a dedicated internal listener; do not share ingress/pull/admin/metrics ports.\n- Worker lease operations are intentionally outside MCP scope.\n\n## Queue Backend Modes\n\n```hcl\n# Default durable mode\nqueue sqlite\n\n# Ephemeral development/testing mode\nqueue memory\n\n# Shared database mode (v2.2.0+)\nqueue postgres\n```\n\nPostgres runtime wiring:\n\n```bash\nexport HOOKAIDO_POSTGRES_DSN='postgres://user:pass@db.internal/hookaido?sslmode=require'\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\n```\n\n## Admin API Reads\n\n```bash\n# Health summary\ncurl -sS \"http://127.0.0.1:2019/healthz\"\n\n# Detailed diagnostics\ncurl -sS \"http://127.0.0.1:2019/healthz?details=1\"\n\n# Backlog trends\ncurl -sS \"http://127.0.0.1:2019/backlog/trends?window=1h&step=5m\"\n\n# Dead-letter queue\ncurl -sS \"http://127.0.0.1:2019/dlq?limit=50\"\n```\n\n## Admin API Mutations\n\nUse `X-Hookaido-Audit-Reason` and keep reasons actionable.\n\n```bash\n# Requeue DLQ items\ncurl -sS -X POST \"http://127.0.0.1:2019/dlq/requeue\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-Hookaido-Audit-Reason: retry-after-fix\" \\\n  -d '{\"ids\":[\"evt_1\",\"evt_2\"]}'\n\n# Delete DLQ items\ncurl -sS -X POST \"http://127.0.0.1:2019/dlq/delete\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-Hookaido-Audit-Reason: remove-invalid-payloads\" \\\n  -d '{\"ids\":[\"evt_3\"]}'\n```\n\n## SSE Streaming (v2.5.3+)\n\nConnect a persistent SSE stream instead of polling dequeue:\n\n```bash\n# Stream events in real time (persistent connection, server pushes)\ncurl -sS -N \"http://localhost:9443/pull/github/stream\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\"\n\n# ACK a streamed event (same endpoint as pull)\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\"}'\n```\n\nNotes:\n- Multiple concurrent SSE connections act as competing consumers.\n- ACK/NACK/extend operations use the same POST endpoints as pull mode.\n- Prometheus metrics are emitted per route.\n\n## MCP Role Patterns\n\n```bash\n# Read-only diagnostics\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\n\n# Queue mutation workflows\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db \\\n  --enable-mutations --role operate --principal ops@example.test\n\n# Full admin control (includes runtime operations)\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db \\\n  --enable-mutations --enable-runtime-control --role admin \\\n  --principal ops@example.test --pid-file ./hookaido.pid\n```\n\n## Claude Code MCP Plugin Config\n\nRegister Hookaido as a Claude Code MCP plugin in `.claude/settings.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"hookaido\": {\n      \"command\": \"hookaido\",\n      \"args\": [\n        \"mcp\", \"serve\",\n        \"--config\", \"./Hookaidofile\",\n        \"--db\", \"./.data/hookaido.db\",\n        \"--role\", \"read\"\n      ]\n    }\n  }\n}\n```\n\nFor operate role (queue mutations enabled):\n\n```json\n{\n  \"mcpServers\": {\n    \"hookaido\": {\n      \"command\": \"hookaido\",\n      \"args\": [\n        \"mcp\", \"serve\",\n        \"--config\", \"./Hookaidofile\",\n        \"--db\", \"./.data/hookaido.db\",\n        \"--enable-mutations\",\n        \"--role\", \"operate\",\n        \"--principal\", \"claude\"\n      ]\n    }\n  }\n}\n```\n\nUse `~/.claude/settings.json` for global registration across all projects.\n\nFile v2.6.0:RELEASE_NOTES.md\n\n# Release Notes\n\n## GitHub Release Summary\n\nRecommended tag: `v2.6.0`\n\nFeature update pinning to upstream Hookaido `v2.6.0`.\nNew: Stripe and Cituro HMAC providers, SSE streaming endpoint, Claude Code MCP plugin guidance.\n\n## v2.6.0 - 2026-04-21\n\nFeature update pinning to upstream Hookaido `v2.6.0`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.6.0`.\n- Added `provider stripe` and `provider cituro` to provider-compatible HMAC config (v2.6.0 upstream).\n- Added SSE streaming playbook: `GET {pull.path}/stream` for real-time webhook delivery without polling (v2.5.3 upstream).\n- Added Claude Code MCP plugin configuration examples (`.claude/settings.json`) for read and operate roles.\n\n### Compatibility\n\nAdditive coverage. All existing skill workflows remain unchanged.\n\n## v2.2.2 - 2026-04-15\n\nPerformance update pinning to upstream Hookaido `v2.2.2`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.2`.\n- Upstream fix: queue dequeue loop now uses event-driven channel notification instead of 25ms polling. Enqueue signals waiting Dequeue goroutines immediately; fallback polling raised to 1s for delayed/retry items only. Idle CPU drops from ~26% to <1% (SQLite and PostgreSQL backends).\n\n### Compatibility\n\nNo new features. All existing skill workflows remain unchanged.\n\n## v2.2.1 - 2026-03-30\n\nBugfix-only update pinning to upstream Hookaido `v2.2.1`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.1`.\n- Upstream fixes: dispatcher delivery logging (previously silent), zero-target route warning, hot-reload for delivery config changes via `--watch`/SIGHUP.\n\n### Compatibility\n\nNo new features. All existing skill workflows remain unchanged.\n\n## v2.2.0 - 2026-03-28\n\nThis release updates the public Hookaido skill to upstream Hookaido `v2.2.0`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.0`.\n- Added `deliver exec` playbook for subprocess delivery (payload on stdin, exit-code retry semantics).\n- Added provider-compatible HMAC playbook for GitHub (`X-Hub-Signature-256`) and Gitea/Forgejo (`X-Gitea-Signature`).\n- Updated operations reference with exec delivery and provider-HMAC config examples.\n\n### Compatibility\n\nAdditive v2.2.0 coverage includes:\n\n- `deliver exec` for local script/binary execution with env-var metadata and exit-code retry semantics\n- `auth hmac { provider github }` / `auth hmac { provider gitea }` for native webhook signature verification\n- Custom outbound headers in deliver blocks with placeholder interpolation\n\nAll existing skill workflows remain unchanged.\n\n## v2.0.0 - 2026-03-09\n\nThis release updates the public Hookaido skill to upstream Hookaido `v2.0.0` and prepares the repository for distribution via its public GitHub URL.\n\n### Highlights\n\n- Pinned all binary installer actions to Hookaido `v2.0.0`.\n- Updated the fallback installer script with the official `v2.0.0` SHA256 checksums for macOS, Linux, and Windows on `amd64` and `arm64`.\n- Switched the skill homepage metadata to the public skill repository: `https://github.com/7schmiede/claw-skill-hookaido`.\n- Documented source-based installation from the public upstream repo: `go install github.com/nuetzliches/hookaido/cmd/hookaido@v2.0.0`.\n\n### Compatibility\n\nThis skill keeps the established inbound, outbound, and pull-based workflow as the default path.\nHookaido v2 capabilities are documented as additive options so existing skill usage does not receive breaking changes by default.\n\nAdditive v2 coverage includes:\n\n- `queue postgres` as an optional backend alongside the existing defaults\n- HTTP and gRPC pull-worker guidance\n- Batch `ack` and batch `nack` pull operations\n- `config validate --strict-secrets`\n- `verify-release` for public release verification\n\n### Documentation Updates\n\n- Refreshed [SKILL.md](SKILL.md) to reflect Hookaido v2.0.0 terminology and workflow guidance.\n- Expanded [references/operations.md](references/operations.md) with Postgres runtime examples, batch pull API calls, and release verification commands.\n- Added [README.md](README.md) so the repo is ready to be consumed directly as a public skill repository.\n\n### Notes\n\n- Upstream modular architecture changes in Hookaido v2.0.0 are treated as opt-in guidance in this skill rather than mandatory workflow changes.\n- The skill name now matches the repository folder name, which fixes skill validation in the current layout.\n\nFile v2.6.0:skill-card.md\n\n## Description:\n\nHookaido Webhook Integration helps agents configure, run, and troubleshoot Hookaido webhook ingress, delivery, pull consumption, queue backends, HMAC verification, MCP operations, and DLQ triage.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[7schmiede](https://clawhub.ai/user/7schmiede)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operations engineers use this skill to implement Hookaido webhook flows, validate Hookaidofile configuration, operate pull or delivery runtimes, and triage queue or dead-letter behavior.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill may install or invoke a local Hookaido binary from an upstream release source.\n\nMitigation: Use a trusted install path and prefer the pinned, SHA256-verifying fallback installer or another verified release process before running the binary.\n\nRisk: MCP registration can persist local tool access beyond a single task.\n\nMitigation: Keep MCP registration project-local where possible and begin with the documented read-only role.\n\nRisk: Queue mutations and DLQ deletion can alter operational webhook state.\n\nMitigation: Inspect queue and DLQ items first, require clear operator intent, use audit reasons, and enable mutation or admin roles only for deliberate operational work.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/7schmiede/skills/hookaido)\n- [Public skill repository](https://github.com/7schmiede/claw-skill-hookaido)\n- [Upstream Hookaido project](https://github.com/nuetzliches/hookaido)\n- [Hookaido Operations Reference](references/operations.md)\n- [Release Notes](RELEASE_NOTES.md)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands, Configuration]\n\n**Output Format:** [Markdown with command snippets, HCL/JSON configuration examples, and operational guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May propose local CLI installation, MCP registration, webhook runtime commands, API calls, and queue mutation steps depending on operator intent.]\n\n## Skill Version(s):\n\n2.6.0 (source: SKILL.md frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v2.6.0:agents/openai.yaml\n\ninterface:\n  display_name: \"Hookaido Operator\"\n  short_description: \"Webhook/webhooks flows, queue ops, MCP, and gRPC-pull\"\n  default_prompt: \"Use this skill for Hookaido inbound/outbound webhook flows, queue triage, MCP operations, and HTTP/gRPC pull workers.\"\n\nArchive v2.2.4: 8 files, 12766 bytes\n\nFiles: agents/openai.yaml (266b), README.md (1028b), references/operations.md (8032b), RELEASE_NOTES.md (3984b), scripts/install_hookaido.sh (4881b), scripts/publish.sh (973b), SKILL.md (11362b), _meta.json (127b)\n\nFile v2.2.4:SKILL.md\n\n---\r\nname: hookaido\r\nversion: \"2.2.4\"\r\ndescription: >-\r\n  Webhook infrastructure for receiving, queuing, and delivering webhooks.\r\n  Operate Hookaido webhook ingress, durable webhook queue (SQLite/Postgres),\r\n  webhook delivery (HTTP push, subprocess exec, pull API), webhook signature\r\n  verification (HMAC, GitHub webhooks, Gitea webhooks), dead-letter queue,\r\n  and webhook retry policies. Use when tasks involve webhook endpoint\r\n  configuration (Hookaidofile), webhook queue backends (sqlite, memory,\r\n  postgres), hookaido CLI (run, config fmt, config validate, mcp serve),\r\n  webhook consumption (dequeue/ack/nack/extend) over HTTP or gRPC, subprocess\r\n  webhook handlers (deliver exec), webhook provider HMAC (GitHub/Gitea/Stripe),\r\n  Admin API webhook backlog/DLQ triage, or production webhook hardening.\r\nmetadata:\r\n  openclaw:\r\n    homepage: https://github.com/7schmiede/claw-skill-hookaido\r\n    emoji: \"\\U0001FA9D\"\r\n    primaryEnv: HOOKAIDO_PULL_TOKEN\r\n    requires:\r\n      bins:\r\n        - hookaido\r\n      env:\r\n        - HOOKAIDO_PULL_TOKEN\r\n        - HOOKAIDO_INGRESS_SECRET\r\n    install:\r\n      - id: go-install\r\n        kind: go\r\n        package: github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.2\r\n        bins:\r\n          - hookaido\r\n      - id: download-darwin-amd64\r\n        kind: download\r\n        os:\r\n          - darwin\r\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.2/hookaido_v2.2.2_darwin_amd64.tar.gz\r\n        archive: tar.gz\r\n        extract: true\r\n        stripComponents: 1\r\n        targetDir: ~/.local/bin\r\n        bins:\r\n          - hookaido\r\n        label: Download hookaido v2.2.2 (macOS amd64)\r\n      - id: download-darwin-arm64\r\n        kind: download\r\n        os:\r\n          - darwin\r\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.2/hookaido_v2.2.2_darwin_arm64.tar.gz\r\n        archive: tar.gz\r\n        extract: true\r\n        stripComponents: 1\r\n        targetDir: ~/.local/bin\r\n        bins:\r\n          - hookaido\r\n        label: Download hookaido v2.2.2 (macOS arm64)\r\n      - id: download-linux-amd64\r\n        kind: download\r\n        os:\r\n          - linux\r\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.2/hookaido_v2.2.2_linux_amd64.tar.gz\r\n        archive: tar.gz\r\n        extract: true\r\n        stripComponents: 1\r\n        targetDir: ~/.local/bin\r\n        bins:\r\n          - hookaido\r\n        label: Download hookaido v2.2.2 (Linux amd64)\r\n      - id: download-linux-arm64\r\n        kind: download\r\n        os:\r\n          - linux\r\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.2/hookaido_v2.2.2_linux_arm64.tar.gz\r\n        archive: tar.gz\r\n        extract: true\r\n        stripComponents: 1\r\n        targetDir: ~/.local/bin\r\n        bins:\r\n          - hookaido\r\n        label: Download hookaido v2.2.2 (Linux arm64)\r\n      - id: download-windows-amd64\r\n        kind: download\r\n        os:\r\n          - win32\r\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.2/hookaido_v2.2.2_windows_amd64.zip\r\n        archive: zip\r\n        extract: true\r\n        targetDir: ~/.openclaw/tools/hookaido\r\n        bins:\r\n          - hookaido\r\n        label: Download hookaido v2.2.2 (Windows amd64)\r\n      - id: download-windows-arm64\r\n        kind: download\r\n        os:\r\n          - win32\r\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.2/hookaido_v2.2.2_windows_arm64.zip\r\n        archive: zip\r\n        extract: true\r\n        targetDir: ~/.openclaw/tools/hookaido\r\n        bins:\r\n          - hookaido\r\n        label: Download hookaido v2.2.2 (Windows arm64)\r\n---\r\n\r\n# Hookaido\r\n\r\n## Overview\r\n\r\nImplement and troubleshoot Hookaido with a config-first workflow: edit `Hookaidofile`, validate, run, exercise ingress/pull/exec flows, then diagnose queue health and DLQ behavior.\r\nTreat Hookaido v2.2.2's modular architecture as additive in this skill: keep the existing workflow intact by default, and opt into modules such as `postgres`, gRPC workers, subprocess delivery (`deliver exec`), or release verification only when they materially help the task.\r\nUse conservative, reversible changes and validate before runtime operations.\r\n\r\n## Workflow\r\n\r\n1. Confirm target topology: inbound+pull (HTTP or gRPC), push outbound, subprocess exec, or internal queue, plus the queue backend (`sqlite`, `memory`, or `postgres`).\r\n2. Choose runtime mode and ensure `hookaido` exists where tools execute.\r\n   - Host-binary mode: use the install action from `metadata.openclaw.install`.\r\n   - Host fallback: run `bash {baseDir}/scripts/install_hookaido.sh` (pinned `v2.2.2`, SHA256-verified).\r\n   - Public repo/source mode: use the public upstream repo `github.com/nuetzliches/hookaido` via `go install github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.2` when a source-based install is preferred.\r\n   - Docker-sandbox mode: use a sandbox image that already includes `hookaido` (preferred), or install inside sandbox via `agents.defaults.sandbox.docker.setupCommand`.\r\n   - Keep host install actions available as fallback and to satisfy `metadata.openclaw.requires.bins`.\r\n3. Inspect and update `Hookaidofile` minimally.\r\n4. Run format and validation before starting or reloading:\r\n   - `hookaido config fmt --config ./Hookaidofile`\r\n   - `hookaido config validate --config ./Hookaidofile`\r\n   - `hookaido config validate --config ./Hookaidofile --strict-secrets` when secret refs or Vault-backed config are involved.\r\n5. Start runtime and verify health:\r\n   - `hookaido run --config ./Hookaidofile --db ./.data/hookaido.db`\r\n   - `hookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"` when `queue postgres` is selected.\r\n   - `curl http://127.0.0.1:2019/healthz?details=1`\r\n6. Validate end-to-end behavior:\r\n   - ingress request accepted and queued\r\n   - consumer `dequeue`/`ack`/`nack`/`extend` path works (HTTP pull, batch `ack`/`nack`, plus gRPC pull when enabled)\r\n7. For incidents, inspect backlog and DLQ first, then mutate.\r\n\r\n## Task Playbooks\r\n\r\n### Configure Ingress and Pull Consumption\r\n\r\n1. Define a route with explicit auth and pull path (HTTP pull, optional gRPC pull worker listener).\r\n2. Keep secrets in env/file refs, never inline.\r\n3. Verify route and global pull auth are consistent.\r\n4. Test with a real webhook payload and a dequeue/ack cycle, using batch `ack`/`nack` when worker throughput matters.\r\n\r\nPrefer this baseline:\r\n\r\n```hcl\r\ningress {\r\n  listen :8080\r\n}\r\n\r\npull_api {\r\n  listen :9443\r\n  grpc_listen :9943 # optional gRPC pull-worker listener\r\n  auth token env:HOOKAIDO_PULL_TOKEN\r\n}\r\n\r\n/webhooks/github {\r\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\r\n  pull { path /pull/github }\r\n}\r\n```\r\n\r\n### Configure Push Delivery\r\n\r\n1. Use push delivery only when inbound connectivity to the service is acceptable.\r\n2. Set timeout and retry policy explicitly.\r\n3. Validate downstream idempotency since delivery is at-least-once.\r\n\r\n```hcl\r\n/webhooks/stripe {\r\n  auth hmac env:STRIPE_SIGNING_SECRET\r\n  deliver \"https://billing.internal/stripe\" {\r\n    retry exponential max 8 base 2s cap 2m jitter 0.2\r\n    timeout 10s\r\n  }\r\n}\r\n```\r\n\r\n### Configure Subprocess Delivery (`deliver exec`)\r\n\r\n1. Use exec delivery when the target is a local script or binary, not an HTTP service.\r\n2. Payload is piped to stdin; metadata arrives as env vars (`HOOKAIDO_ROUTE`, `HOOKAIDO_EVENT_ID`, `HOOKAIDO_ATTEMPT`, etc.).\r\n3. Exit code determines retry behavior: `0` = ack, `1-125` = retry, `126`/`127` = immediate DLQ.\r\n4. `sign` directives are not supported with exec (compile error).\r\n\r\n```hcl\r\n/webhooks/github {\r\n  auth hmac {\r\n    provider github\r\n    secret env:GITHUB_WEBHOOK_SECRET\r\n  }\r\n  deliver exec \"/opt/hooks/deploy.sh\" {\r\n    timeout 30s\r\n    retry exponential max 3 base 1s cap 30s jitter 0.2\r\n    env DEPLOY_ENV production\r\n    env NOTIFY_URL {env.SLACK_WEBHOOK_URL}\r\n  }\r\n}\r\n```\r\n\r\n### Configure Provider-Compatible HMAC\r\n\r\n1. Use `provider github` or `provider gitea` for webhook providers that use their own signature format.\r\n2. Provider mode disables timestamp/nonce replay protection (providers do not send those headers).\r\n3. `signature_header`, `timestamp_header`, `nonce_header`, and `tolerance` are forbidden in provider mode (compile error).\r\n\r\n```hcl\r\n/webhooks/github {\r\n  auth hmac {\r\n    provider github\r\n    secret env:GITHUB_WEBHOOK_SECRET\r\n  }\r\n  pull { path /pull/github }\r\n}\r\n\r\n/webhooks/gitea {\r\n  auth hmac {\r\n    provider gitea\r\n    secret env:GITEA_WEBHOOK_SECRET\r\n  }\r\n  pull { path /pull/gitea }\r\n}\r\n```\r\n\r\n### Configure Queue Backends\r\n\r\n1. Default to `sqlite` unless the task explicitly needs ephemeral dev mode or shared Postgres storage.\r\n2. Treat `memory` and `postgres` as additive v2 modules, not replacements for existing sqlite workflows.\r\n3. When using `postgres`, document the DSN source and validate health plus backlog endpoints after startup.\r\n\r\nPrefer these patterns:\r\n\r\n```hcl\r\nqueue sqlite\r\n\r\nqueue memory\r\n\r\nqueue postgres\r\n```\r\n\r\n### Operate Queue and DLQ\r\n\r\n1. Start with health details and backlog endpoints.\r\n2. Inspect DLQ before requeue or delete.\r\n3. If requeueing many items, explain expected impact and rollback path.\r\n4. Require clear operator reason strings for mutating admin calls.\r\n\r\nUse:\r\n\r\n- `GET /healthz?details=1`\r\n- `GET /backlog/trends`\r\n- `GET /dlq`\r\n- `POST /dlq/requeue`\r\n- `POST /dlq/delete`\r\n\r\n### Use MCP Mode for AI Operations\r\n\r\n1. Default to `--role read` for diagnostics.\r\n2. Enable mutations only with explicit operator intent:\r\n   - `--enable-mutations --role operate --principal <identity>`\r\n3. Enable runtime control only for admin workflows:\r\n   - `--enable-runtime-control --role admin --pid-file <path>`\r\n4. Include `reason` for mutation calls and keep it specific.\r\n\r\n### Verify Public Releases\r\n\r\n1. Prefer official release assets from the public Hookaido repo.\r\n2. When supply-chain assurance matters, validate checksums, signature material, and provenance before rollout.\r\n3. Keep verification optional by default so existing skill flows do not become heavier unless the task requires it.\r\n\r\nUse:\r\n\r\n- `hookaido verify-release --checksums ./hookaido_v2.2.2_checksums.txt --require-provenance`\r\n\r\n## Validation Checklist\r\n\r\n- `hookaido config validate` returns success before runtime start/reload.\r\n- `hookaido config validate --strict-secrets` is used when secret refs, Vault, or public-release rollout validation matters.\r\n- Health endpoint is reachable and reports expected queue/backend state.\r\n- Pull consumer can `dequeue`, `ack`, `nack`, and `extend` with valid token (HTTP and optional gRPC transport), including batch `ack`/`nack` when enabled.\r\n- For push mode, retry/timeout behavior is explicitly configured.\r\n- For exec mode, handler script is executable, reads stdin, and uses exit codes correctly (0=ack, non-zero=retry, 126/127=DLQ).\r\n- For `queue postgres`, runtime is started with `--postgres-dsn` or `HOOKAIDO_POSTGRES_DSN`.\r\n- Any DLQ mutation is scoped, justified, and logged.\r\n\r\n## Safety Rules\r\n\r\n- Do not disable auth to \"make tests pass.\"\r\n- Do not suggest direct mutations before read-only diagnostics.\r\n- Treat queue operations as at-least-once; require idempotent handlers.\r\n- Keep secrets in `env:` or `file:` refs.\r\n\r\n## References\r\n\r\n- Read `references/operations.md` for command snippets and API payload templates.\n\nFile v2.2.4:README.md\n\n# hookaido\r\n\r\nPublic OpenClaw skill for [Hookaido](https://github.com/nuetzliches/hookaido) — webhook infrastructure that just works.\r\n\r\nRepository link for skill distribution:\r\n\r\n- `https://github.com/7schmiede/claw-skill-hookaido`\r\n\r\nUpstream Hookaido project:\r\n\r\n- `https://github.com/nuetzliches/hookaido`\r\n\r\nThis skill is pinned to Hookaido `v2.2.2` and keeps existing inbound/outbound/pull workflows as the default path.\r\nNew capabilities such as `deliver exec` (subprocess delivery), provider-compatible HMAC (GitHub/Gitea), `queue postgres`, gRPC pull workers, batch `ack`/`nack`, and release verification are documented as additive modules so existing usage does not receive breaking changes by default.\r\n\r\nMain files:\r\n\r\n- `SKILL.md` for skill metadata and operating guidance\r\n- `references/operations.md` for install, runtime, and API command examples\r\n- `scripts/install_hookaido.sh` for pinned release-binary installation with SHA256 verification\r\n- `RELEASE_NOTES.md` for the current public skill release summary\n\nFile v2.2.4:_meta.json\n\n{\n  \"ownerId\": \"kn70n9zjjpmw2dg19a8n5w8bm1813vkf\",\n  \"slug\": \"hookaido\",\n  \"version\": \"2.2.4\",\n  \"publishedAt\": 1776251478837\n}\n\nFile v2.2.4:references/operations.md\n\n# Hookaido Operations Reference\r\n\r\nUse this file for concrete command syntax and request payloads.\r\n\r\n## Install Hookaido\r\n\r\nOpenClaw supports two runtime variants.\r\n\r\nPublic repositories:\r\n\r\n- Upstream project: `https://github.com/nuetzliches/hookaido`\r\n- Public skill repo: `https://github.com/7schmiede/claw-skill-hookaido`\r\n\r\n### Variant A: Host Binary (Gateway/Host)\r\n\r\n- Use one of the skill installer actions from `metadata.openclaw.install` (platform + architecture specific download).\r\n- Choose the artifact that matches your host architecture (`amd64` or `arm64`).\r\n- The OpenClaw download URLs are pinned to Hookaido `v2.2.1`.\r\n- macOS/Linux installers extract to `~/.local/bin` (with `stripComponents: 1`).\r\n- Windows installers extract to `~/.openclaw/tools/hookaido`.\r\n\r\nDirect CLI fallback:\r\n\r\n```bash\r\ngo install github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.1\r\n```\r\n\r\nRelease-binary fallback from this skill folder:\r\n\r\n```bash\r\nbash {baseDir}/scripts/install_hookaido.sh\r\n```\r\n\r\nThe fallback installer is hardened:\r\n\r\n- Defaults to pinned `v2.2.1` (no dynamic `latest` lookup).\r\n- Verifies SHA256 of the downloaded release artifact before extraction/install.\r\n\r\nOptional pins/overrides for the installer script:\r\n\r\n```bash\r\n# Default pinned install, custom location\r\nHOOKAIDO_INSTALL_DIR=\"$HOME/bin\" bash {baseDir}/scripts/install_hookaido.sh\r\n\r\n# Non-default release requires explicit checksum\r\nHOOKAIDO_VERSION=v2.0.1 \\\r\nHOOKAIDO_SHA256=\"<artifact-sha256>\" \\\r\nbash {baseDir}/scripts/install_hookaido.sh\r\n```\r\n\r\n### Variant B: Docker Sandbox\r\n\r\n- OpenClaw supports Docker sandbox mode via `sandboxing.enabled: true` and `sandboxing.type: docker`.\r\n- Preferred: provide a custom sandbox image with `hookaido` preinstalled, and pin the image by immutable digest.\r\n- Optional: use `agents.defaults.sandbox.docker.setupCommand` to install `hookaido` inside the container at startup.\r\n- Keep `metadata.openclaw.install` as fallback and for `metadata.openclaw.requires.bins` checks on the host.\r\n\r\n## Core CLI Commands\r\n\r\n```bash\r\n# Validate and format config\r\nhookaido config fmt --config ./Hookaidofile\r\nhookaido config validate --config ./Hookaidofile\r\nhookaido config validate --config ./Hookaidofile --strict-secrets\r\n\r\n# Start runtime\r\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db\r\n\r\n# Start runtime with Postgres queue backend\r\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\r\n\r\n# Start runtime with live config watch\r\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db --watch\r\n\r\n# Start MCP server (read-only)\r\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\r\n\r\n# Verify a public release bundle before rollout\r\nhookaido verify-release \\\r\n  --checksums ./hookaido_v2.2.1_checksums.txt \\\r\n  --public-key ./hookaido_v2.2.1_checksums.txt.pub.pem \\\r\n  --require-provenance\r\n```\r\n\r\n## Minimal Pull-Mode Config\r\n\r\n```hcl\r\ningress {\r\n  listen :8080\r\n}\r\n\r\npull_api {\r\n  listen :9443\r\n  auth token env:HOOKAIDO_PULL_TOKEN\r\n}\r\n\r\n/webhooks/github {\r\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\r\n  pull { path /pull/github }\r\n}\r\n```\r\n\r\n## Exec Delivery Config (v2.2.0+)\r\n\r\n```hcl\r\n/webhooks/github {\r\n  auth hmac {\r\n    provider github\r\n    secret env:GITHUB_WEBHOOK_SECRET\r\n  }\r\n  deliver exec \"/opt/hooks/deploy.sh\" {\r\n    timeout 30s\r\n    retry exponential max 3 base 1s cap 30s jitter 0.2\r\n    env DEPLOY_ENV production\r\n  }\r\n}\r\n```\r\n\r\nExit codes: `0` = ack, `75`/`1-125` = retry, `126`/`127` = immediate DLQ.\r\nMetadata env vars: `HOOKAIDO_ROUTE`, `HOOKAIDO_EVENT_ID`, `HOOKAIDO_CONTENT_TYPE`, `HOOKAIDO_ATTEMPT`, `HOOKAIDO_HEADER_*`.\r\n\r\n## Provider-Compatible HMAC Config (v2.2.0+)\r\n\r\n```hcl\r\n# GitHub\r\n/webhooks/github {\r\n  auth hmac {\r\n    provider github\r\n    secret env:GITHUB_WEBHOOK_SECRET\r\n  }\r\n  pull { path /pull/github }\r\n}\r\n\r\n# Gitea / Forgejo\r\n/webhooks/gitea {\r\n  auth hmac {\r\n    provider gitea\r\n    secret env:GITEA_WEBHOOK_SECRET\r\n  }\r\n  pull { path /pull/gitea }\r\n}\r\n```\r\n\r\n## Pull API Calls\r\n\r\nAssume base URL `http://localhost:9443/pull/github` and token in `HOOKAIDO_PULL_TOKEN`.\r\n\r\n```bash\r\n# Dequeue\r\ncurl -sS -X POST \"http://localhost:9443/pull/github/dequeue\" \\\r\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -d '{\"batch\":10,\"lease_ttl\":\"30s\",\"max_wait\":\"5s\"}'\r\n\r\n# Ack\r\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\r\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -d '{\"lease_id\":\"lease_xyz\"}'\r\n\r\n# Batch ack (v2.2.0+)\r\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\r\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -d '{\"lease_ids\":[\"lease_a\",\"lease_b\"]}'\r\n\r\n# Nack (requeue with delay)\r\ncurl -sS -X POST \"http://localhost:9443/pull/github/nack\" \\\r\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -d '{\"lease_id\":\"lease_xyz\",\"delay\":\"5s\",\"dead\":false}'\r\n\r\n# Extend lease\r\ncurl -sS -X POST \"http://localhost:9443/pull/github/extend\" \\\r\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -d '{\"lease_id\":\"lease_xyz\",\"lease_ttl\":\"30s\"}'\r\n\r\n# Batch nack (v2.2.0+)\r\ncurl -sS -X POST \"http://localhost:9443/pull/github/nack\" \\\r\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -d '{\"lease_ids\":[\"lease_a\",\"lease_b\"],\"delay\":\"5s\",\"dead\":false}'\r\n```\r\n\r\n## Optional gRPC Pull-Worker Mode (`v1.4.0+`)\r\n\r\nEnable gRPC pull-worker transport alongside HTTP pull:\r\n\r\n```hcl\r\npull_api {\r\n  listen :9443\r\n  grpc_listen :9943\r\n  auth token env:HOOKAIDO_PULL_TOKEN\r\n}\r\n\r\n/webhooks/github {\r\n  pull { path /pull/github }\r\n}\r\n```\r\n\r\nUse gRPC workers with the same lease semantics and operation parity as Pull HTTP:\r\n\r\n- `Dequeue` -> `POST {endpoint}/dequeue`\r\n- `Ack` -> `POST {endpoint}/ack`\r\n- `Nack` -> `POST {endpoint}/nack`\r\n- `Extend` -> `POST {endpoint}/extend`\r\n\r\nNotes:\r\n\r\n- Worker gRPC reuses pull token auth and pull endpoint routing.\r\n- Keep `grpc_listen` on a dedicated internal listener; do not share ingress/pull/admin/metrics ports.\r\n- Worker lease operations are intentionally outside MCP scope.\r\n\r\n## Queue Backend Modes\r\n\r\n```hcl\r\n# Default durable mode\r\nqueue sqlite\r\n\r\n# Ephemeral development/testing mode\r\nqueue memory\r\n\r\n# Shared database mode (v2.2.0+)\r\nqueue postgres\r\n```\r\n\r\nPostgres runtime wiring:\r\n\r\n```bash\r\nexport HOOKAIDO_POSTGRES_DSN='postgres://user:pass@db.internal/hookaido?sslmode=require'\r\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\r\n```\r\n\r\n## Admin API Reads\r\n\r\n```bash\r\n# Health summary\r\ncurl -sS \"http://127.0.0.1:2019/healthz\"\r\n\r\n# Detailed diagnostics\r\ncurl -sS \"http://127.0.0.1:2019/healthz?details=1\"\r\n\r\n# Backlog trends\r\ncurl -sS \"http://127.0.0.1:2019/backlog/trends?window=1h&step=5m\"\r\n\r\n# Dead-letter queue\r\ncurl -sS \"http://127.0.0.1:2019/dlq?limit=50\"\r\n```\r\n\r\n## Admin API Mutations\r\n\r\nUse `X-Hookaido-Audit-Reason` and keep reasons actionable.\r\n\r\n```bash\r\n# Requeue DLQ items\r\ncurl -sS -X POST \"http://127.0.0.1:2019/dlq/requeue\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -H \"X-Hookaido-Audit-Reason: retry-after-fix\" \\\r\n  -d '{\"ids\":[\"evt_1\",\"evt_2\"]}'\r\n\r\n# Delete DLQ items\r\ncurl -sS -X POST \"http://127.0.0.1:2019/dlq/delete\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -H \"X-Hookaido-Audit-Reason: remove-invalid-payloads\" \\\r\n  -d '{\"ids\":[\"evt_3\"]}'\r\n```\r\n\r\n## MCP Role Patterns\r\n\r\n```bash\r\n# Read-only diagnostics\r\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\r\n\r\n# Queue mutation workflows\r\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db \\\r\n  --enable-mutations --role operate --principal ops@example.test\r\n\r\n# Full admin control (includes runtime operations)\r\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db \\\r\n  --enable-mutations --enable-runtime-control --role admin \\\r\n  --principal ops@example.test --pid-file ./hookaido.pid\r\n```\n\nFile v2.2.4:RELEASE_NOTES.md\n\n# Release Notes\r\n\r\n## GitHub Release Summary\r\n\r\nRecommended tag: `v2.2.2`\r\n\r\nPerformance fix pinning to upstream Hookaido `v2.2.2`.\r\nUpstream fix: event-driven dequeue wake-up replaces 25ms polling, reducing idle CPU from ~26% to <1%.\r\n\r\n## v2.2.2 - 2026-04-15\r\n\r\nPerformance update pinning to upstream Hookaido `v2.2.2`.\r\n\r\n### Highlights\r\n\r\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.2`.\r\n- Upstream fix: queue dequeue loop now uses event-driven channel notification instead of 25ms polling. Enqueue signals waiting Dequeue goroutines immediately; fallback polling raised to 1s for delayed/retry items only. Idle CPU drops from ~26% to <1% (SQLite and PostgreSQL backends).\r\n\r\n### Compatibility\r\n\r\nNo new features. All existing skill workflows remain unchanged.\r\n\r\n## v2.2.1 - 2026-03-30\r\n\r\nBugfix-only update pinning to upstream Hookaido `v2.2.1`.\r\n\r\n### Highlights\r\n\r\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.1`.\r\n- Upstream fixes: dispatcher delivery logging (previously silent), zero-target route warning, hot-reload for delivery config changes via `--watch`/SIGHUP.\r\n\r\n### Compatibility\r\n\r\nNo new features. All existing skill workflows remain unchanged.\r\n\r\n## v2.2.0 - 2026-03-28\r\n\r\nThis release updates the public Hookaido skill to upstream Hookaido `v2.2.0`.\r\n\r\n### Highlights\r\n\r\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.0`.\r\n- Added `deliver exec` playbook for subprocess delivery (payload on stdin, exit-code retry semantics).\r\n- Added provider-compatible HMAC playbook for GitHub (`X-Hub-Signature-256`) and Gitea/Forgejo (`X-Gitea-Signature`).\r\n- Updated operations reference with exec delivery and provider-HMAC config examples.\r\n\r\n### Compatibility\r\n\r\nAdditive v2.2.0 coverage includes:\r\n\r\n- `deliver exec` for local script/binary execution with env-var metadata and exit-code retry semantics\r\n- `auth hmac { provider github }` / `auth hmac { provider gitea }` for native webhook signature verification\r\n- Custom outbound headers in deliver blocks with placeholder interpolation\r\n\r\nAll existing skill workflows remain unchanged.\r\n\r\n## v2.0.0 - 2026-03-09\r\n\r\nThis release updates the public Hookaido skill to upstream Hookaido `v2.0.0` and prepares the repository for distribution via its public GitHub URL.\r\n\r\n### Highlights\r\n\r\n- Pinned all binary installer actions to Hookaido `v2.0.0`.\r\n- Updated the fallback installer script with the official `v2.0.0` SHA256 checksums for macOS, Linux, and Windows on `amd64` and `arm64`.\r\n- Switched the skill homepage metadata to the public skill repository: `https://github.com/7schmiede/claw-skill-hookaido`.\r\n- Documented source-based installation from the public upstream repo: `go install github.com/nuetzliches/hookaido/cmd/hookaido@v2.0.0`.\r\n\r\n### Compatibility\r\n\r\nThis skill keeps the established inbound, outbound, and pull-based workflow as the default path.\r\nHookaido v2 capabilities are documented as additive options so existing skill usage does not receive breaking changes by default.\r\n\r\nAdditive v2 coverage includes:\r\n\r\n- `queue postgres` as an optional backend alongside the existing defaults\r\n- HTTP and gRPC pull-worker guidance\r\n- Batch `ack` and batch `nack` pull operations\r\n- `config validate --strict-secrets`\r\n- `verify-release` for public release verification\r\n\r\n### Documentation Updates\r\n\r\n- Refreshed [SKILL.md](SKILL.md) to reflect Hookaido v2.0.0 terminology and workflow guidance.\r\n- Expanded [references/operations.md](references/operations.md) with Postgres runtime examples, batch pull API calls, and release verification commands.\r\n- Added [README.md](README.md) so the repo is ready to be consumed directly as a public skill repository.\r\n\r\n### Notes\r\n\r\n- Upstream modular architecture changes in Hookaido v2.0.0 are treated as opt-in guidance in this skill rather than mandatory workflow changes.\r\n- The skill name now matches the repository folder name, which fixes skill validation in the current layout.\n\nFile v2.2.4:agents/openai.yaml\n\ninterface:\r\n  display_name: \"Hookaido Operator\"\r\n  short_description: \"Webhook/webhooks flows, queue ops, MCP, and gRPC-pull\"\r\n  default_prompt: \"Use this skill for Hookaido inbound/outbound webhook flows, queue triage, MCP operations, and HTTP/gRPC pull workers.\"\n\nArchive v2.2.3: 7 files, 11789 bytes\n\nFiles: agents/openai.yaml (262b), README.md (1008b), references/operations.md (7749b), RELEASE_NOTES.md (3365b), scripts/install_hookaido.sh (4705b), SKILL.md (11067b), _meta.json (127b)\n\nFile v2.2.3:SKILL.md\n\n---\nname: hookaido\nversion: \"2.2.3\"\ndescription: >-\n  Webhook infrastructure for receiving, queuing, and delivering webhooks.\n  Operate Hookaido webhook ingress, durable webhook queue (SQLite/Postgres),\n  webhook delivery (HTTP push, subprocess exec, pull API), webhook signature\n  verification (HMAC, GitHub webhooks, Gitea webhooks), dead-letter queue,\n  and webhook retry policies. Use when tasks involve webhook endpoint\n  configuration (Hookaidofile), webhook queue backends (sqlite, memory,\n  postgres), hookaido CLI (run, config fmt, config validate, mcp serve),\n  webhook consumption (dequeue/ack/nack/extend) over HTTP or gRPC, subprocess\n  webhook handlers (deliver exec), webhook provider HMAC (GitHub/Gitea/Stripe),\n  Admin API webhook backlog/DLQ triage, or production webhook hardening.\nmetadata:\n  openclaw:\n    homepage: https://github.com/7schmiede/claw-skill-hookaido\n    emoji: \"\\U0001FA9D\"\n    primaryEnv: HOOKAIDO_PULL_TOKEN\n    requires:\n      bins:\n        - hookaido\n      env:\n        - HOOKAIDO_PULL_TOKEN\n        - HOOKAIDO_INGRESS_SECRET\n    install:\n      - id: go-install\n        kind: go\n        package: github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.1\n        bins:\n          - hookaido\n      - id: download-darwin-amd64\n        kind: download\n        os:\n          - darwin\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.1/hookaido_v2.2.1_darwin_amd64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.1 (macOS amd64)\n      - id: download-darwin-arm64\n        kind: download\n        os:\n          - darwin\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.1/hookaido_v2.2.1_darwin_arm64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.1 (macOS arm64)\n      - id: download-linux-amd64\n        kind: download\n        os:\n          - linux\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.1/hookaido_v2.2.1_linux_amd64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.1 (Linux amd64)\n      - id: download-linux-arm64\n        kind: download\n        os:\n          - linux\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.1/hookaido_v2.2.1_linux_arm64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.1 (Linux arm64)\n      - id: download-windows-amd64\n        kind: download\n        os:\n          - win32\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.1/hookaido_v2.2.1_windows_amd64.zip\n        archive: zip\n        extract: true\n        targetDir: ~/.openclaw/tools/hookaido\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.1 (Windows amd64)\n      - id: download-windows-arm64\n        kind: download\n        os:\n          - win32\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.1/hookaido_v2.2.1_windows_arm64.zip\n        archive: zip\n        extract: true\n        targetDir: ~/.openclaw/tools/hookaido\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.1 (Windows arm64)\n---\n\n# Hookaido\n\n## Overview\n\nImplement and troubleshoot Hookaido with a config-first workflow: edit `Hookaidofile`, validate, run, exercise ingress/pull/exec flows, then diagnose queue health and DLQ behavior.\nTreat Hookaido v2.2.1's modular architecture as additive in this skill: keep the existing workflow intact by default, and opt into modules such as `postgres`, gRPC workers, subprocess delivery (`deliver exec`), or release verification only when they materially help the task.\nUse conservative, reversible changes and validate before runtime operations.\n\n## Workflow\n\n1. Confirm target topology: inbound+pull (HTTP or gRPC), push outbound, subprocess exec, or internal queue, plus the queue backend (`sqlite`, `memory`, or `postgres`).\n2. Choose runtime mode and ensure `hookaido` exists where tools execute.\n   - Host-binary mode: use the install action from `metadata.openclaw.install`.\n   - Host fallback: run `bash {baseDir}/scripts/install_hookaido.sh` (pinned `v2.2.1`, SHA256-verified).\n   - Public repo/source mode: use the public upstream repo `github.com/nuetzliches/hookaido` via `go install github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.1` when a source-based install is preferred.\n   - Docker-sandbox mode: use a sandbox image that already includes `hookaido` (preferred), or install inside sandbox via `agents.defaults.sandbox.docker.setupCommand`.\n   - Keep host install actions available as fallback and to satisfy `metadata.openclaw.requires.bins`.\n3. Inspect and update `Hookaidofile` minimally.\n4. Run format and validation before starting or reloading:\n   - `hookaido config fmt --config ./Hookaidofile`\n   - `hookaido config validate --config ./Hookaidofile`\n   - `hookaido config validate --config ./Hookaidofile --strict-secrets` when secret refs or Vault-backed config are involved.\n5. Start runtime and verify health:\n   - `hookaido run --config ./Hookaidofile --db ./.data/hookaido.db`\n   - `hookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"` when `queue postgres` is selected.\n   - `curl http://127.0.0.1:2019/healthz?details=1`\n6. Validate end-to-end behavior:\n   - ingress request accepted and queued\n   - consumer `dequeue`/`ack`/`nack`/`extend` path works (HTTP pull, batch `ack`/`nack`, plus gRPC pull when enabled)\n7. For incidents, inspect backlog and DLQ first, then mutate.\n\n## Task Playbooks\n\n### Configure Ingress and Pull Consumption\n\n1. Define a route with explicit auth and pull path (HTTP pull, optional gRPC pull worker listener).\n2. Keep secrets in env/file refs, never inline.\n3. Verify route and global pull auth are consistent.\n4. Test with a real webhook payload and a dequeue/ack cycle, using batch `ack`/`nack` when worker throughput matters.\n\nPrefer this baseline:\n\n```hcl\ningress {\n  listen :8080\n}\n\npull_api {\n  listen :9443\n  grpc_listen :9943 # optional gRPC pull-worker listener\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\n  pull { path /pull/github }\n}\n```\n\n### Configure Push Delivery\n\n1. Use push delivery only when inbound connectivity to the service is acceptable.\n2. Set timeout and retry policy explicitly.\n3. Validate downstream idempotency since delivery is at-least-once.\n\n```hcl\n/webhooks/stripe {\n  auth hmac env:STRIPE_SIGNING_SECRET\n  deliver \"https://billing.internal/stripe\" {\n    retry exponential max 8 base 2s cap 2m jitter 0.2\n    timeout 10s\n  }\n}\n```\n\n### Configure Subprocess Delivery (`deliver exec`)\n\n1. Use exec delivery when the target is a local script or binary, not an HTTP service.\n2. Payload is piped to stdin; metadata arrives as env vars (`HOOKAIDO_ROUTE`, `HOOKAIDO_EVENT_ID`, `HOOKAIDO_ATTEMPT`, etc.).\n3. Exit code determines retry behavior: `0` = ack, `1-125` = retry, `126`/`127` = immediate DLQ.\n4. `sign` directives are not supported with exec (compile error).\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  deliver exec \"/opt/hooks/deploy.sh\" {\n    timeout 30s\n    retry exponential max 3 base 1s cap 30s jitter 0.2\n    env DEPLOY_ENV production\n    env NOTIFY_URL {env.SLACK_WEBHOOK_URL}\n  }\n}\n```\n\n### Configure Provider-Compatible HMAC\n\n1. Use `provider github` or `provider gitea` for webhook providers that use their own signature format.\n2. Provider mode disables timestamp/nonce replay protection (providers do not send those headers).\n3. `signature_header`, `timestamp_header`, `nonce_header`, and `tolerance` are forbidden in provider mode (compile error).\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  pull { path /pull/github }\n}\n\n/webhooks/gitea {\n  auth hmac {\n    provider gitea\n    secret env:GITEA_WEBHOOK_SECRET\n  }\n  pull { path /pull/gitea }\n}\n```\n\n### Configure Queue Backends\n\n1. Default to `sqlite` unless the task explicitly needs ephemeral dev mode or shared Postgres storage.\n2. Treat `memory` and `postgres` as additive v2 modules, not replacements for existing sqlite workflows.\n3. When using `postgres`, document the DSN source and validate health plus backlog endpoints after startup.\n\nPrefer these patterns:\n\n```hcl\nqueue sqlite\n\nqueue memory\n\nqueue postgres\n```\n\n### Operate Queue and DLQ\n\n1. Start with health details and backlog endpoints.\n2. Inspect DLQ before requeue or delete.\n3. If requeueing many items, explain expected impact and rollback path.\n4. Require clear operator reason strings for mutating admin calls.\n\nUse:\n\n- `GET /healthz?details=1`\n- `GET /backlog/trends`\n- `GET /dlq`\n- `POST /dlq/requeue`\n- `POST /dlq/delete`\n\n### Use MCP Mode for AI Operations\n\n1. Default to `--role read` for diagnostics.\n2. Enable mutations only with explicit operator intent:\n   - `--enable-mutations --role operate --principal <identity>`\n3. Enable runtime control only for admin workflows:\n   - `--enable-runtime-control --role admin --pid-file <path>`\n4. Include `reason` for mutation calls and keep it specific.\n\n### Verify Public Releases\n\n1. Prefer official release assets from the public Hookaido repo.\n2. When supply-chain assurance matters, validate checksums, signature material, and provenance before rollout.\n3. Keep verification optional by default so existing skill flows do not become heavier unless the task requires it.\n\nUse:\n\n- `hookaido verify-release --checksums ./hookaido_v2.2.1_checksums.txt --require-provenance`\n\n## Validation Checklist\n\n- `hookaido config validate` returns success before runtime start/reload.\n- `hookaido config validate --strict-secrets` is used when secret refs, Vault, or public-release rollout validation matters.\n- Health endpoint is reachable and reports expected queue/backend state.\n- Pull consumer can `dequeue`, `ack`, `nack`, and `extend` with valid token (HTTP and optional gRPC transport), including batch `ack`/`nack` when enabled.\n- For push mode, retry/timeout behavior is explicitly configured.\n- For exec mode, handler script is executable, reads stdin, and uses exit codes correctly (0=ack, non-zero=retry, 126/127=DLQ).\n- For `queue postgres`, runtime is started with `--postgres-dsn` or `HOOKAIDO_POSTGRES_DSN`.\n- Any DLQ mutation is scoped, justified, and logged.\n\n## Safety Rules\n\n- Do not disable auth to \"make tests pass.\"\n- Do not suggest direct mutations before read-only diagnostics.\n- Treat queue operations as at-least-once; require idempotent handlers.\n- Keep secrets in `env:` or `file:` refs.\n\n## References\n\n- Read `references/operations.md` for command snippets and API payload templates.\n\nFile v2.2.3:README.md\n\n# hookaido\n\nPublic OpenClaw skill for [Hookaido](https://github.com/nuetzliches/hookaido) — webhook infrastructure that just works.\n\nRepository link for skill distribution:\n\n- `https://github.com/7schmiede/claw-skill-hookaido`\n\nUpstream Hookaido project:\n\n- `https://github.com/nuetzliches/hookaido`\n\nThis skill is pinned to Hookaido `v2.2.1` and keeps existing inbound/outbound/pull workflows as the default path.\nNew capabilities such as `deliver exec` (subprocess delivery), provider-compatible HMAC (GitHub/Gitea), `queue postgres`, gRPC pull workers, batch `ack`/`nack`, and release verification are documented as additive modules so existing usage does not receive breaking changes by default.\n\nMain files:\n\n- `SKILL.md` for skill metadata and operating guidance\n- `references/operations.md` for install, runtime, and API command examples\n- `scripts/install_hookaido.sh` for pinned release-binary installation with SHA256 verification\n- `RELEASE_NOTES.md` for the current public skill release summary\n\nFile v2.2.3:_meta.json\n\n{\n  \"ownerId\": \"kn70n9zjjpmw2dg19a8n5w8bm1813vkf\",\n  \"slug\": \"hookaido\",\n  \"version\": \"2.2.3\",\n  \"publishedAt\": 1774887943708\n}\n\nFile v2.2.3:references/operations.md\n\n# Hookaido Operations Reference\n\nUse this file for concrete command syntax and request payloads.\n\n## Install Hookaido\n\nOpenClaw supports two runtime variants.\n\nPublic repositories:\n\n- Upstream project: `https://github.com/nuetzliches/hookaido`\n- Public skill repo: `https://github.com/7schmiede/claw-skill-hookaido`\n\n### Variant A: Host Binary (Gateway/Host)\n\n- Use one of the skill installer actions from `metadata.openclaw.install` (platform + architecture specific download).\n- Choose the artifact that matches your host architecture (`amd64` or `arm64`).\n- The OpenClaw download URLs are pinned to Hookaido `v2.2.1`.\n- macOS/Linux installers extract to `~/.local/bin` (with `stripComponents: 1`).\n- Windows installers extract to `~/.openclaw/tools/hookaido`.\n\nDirect CLI fallback:\n\n```bash\ngo install github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.1\n```\n\nRelease-binary fallback from this skill folder:\n\n```bash\nbash {baseDir}/scripts/install_hookaido.sh\n```\n\nThe fallback installer is hardened:\n\n- Defaults to pinned `v2.2.1` (no dynamic `latest` lookup).\n- Verifies SHA256 of the downloaded release artifact before extraction/install.\n\nOptional pins/overrides for the installer script:\n\n```bash\n# Default pinned install, custom location\nHOOKAIDO_INSTALL_DIR=\"$HOME/bin\" bash {baseDir}/scripts/install_hookaido.sh\n\n# Non-default release requires explicit checksum\nHOOKAIDO_VERSION=v2.0.1 \\\nHOOKAIDO_SHA256=\"<artifact-sha256>\" \\\nbash {baseDir}/scripts/install_hookaido.sh\n```\n\n### Variant B: Docker Sandbox\n\n- OpenClaw supports Docker sandbox mode via `sandboxing.enabled: true` and `sandboxing.type: docker`.\n- Preferred: provide a custom sandbox image with `hookaido` preinstalled, and pin the image by immutable digest.\n- Optional: use `agents.defaults.sandbox.docker.setupCommand` to install `hookaido` inside the container at startup.\n- Keep `metadata.openclaw.install` as fallback and for `metadata.openclaw.requires.bins` checks on the host.\n\n## Core CLI Commands\n\n```bash\n# Validate and format config\nhookaido config fmt --config ./Hookaidofile\nhookaido config validate --config ./Hookaidofile\nhookaido config validate --config ./Hookaidofile --strict-secrets\n\n# Start runtime\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db\n\n# Start runtime with Postgres queue backend\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\n\n# Start runtime with live config watch\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db --watch\n\n# Start MCP server (read-only)\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\n\n# Verify a public release bundle before rollout\nhookaido verify-release \\\n  --checksums ./hookaido_v2.2.1_checksums.txt \\\n  --public-key ./hookaido_v2.2.1_checksums.txt.pub.pem \\\n  --require-provenance\n```\n\n## Minimal Pull-Mode Config\n\n```hcl\ningress {\n  listen :8080\n}\n\npull_api {\n  listen :9443\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\n  pull { path /pull/github }\n}\n```\n\n## Exec Delivery Config (v2.2.0+)\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  deliver exec \"/opt/hooks/deploy.sh\" {\n    timeout 30s\n    retry exponential max 3 base 1s cap 30s jitter 0.2\n    env DEPLOY_ENV production\n  }\n}\n```\n\nExit codes: `0` = ack, `75`/`1-125` = retry, `126`/`127` = immediate DLQ.\nMetadata env vars: `HOOKAIDO_ROUTE`, `HOOKAIDO_EVENT_ID`, `HOOKAIDO_CONTENT_TYPE`, `HOOKAIDO_ATTEMPT`, `HOOKAIDO_HEADER_*`.\n\n## Provider-Compatible HMAC Config (v2.2.0+)\n\n```hcl\n# GitHub\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  pull { path /pull/github }\n}\n\n# Gitea / Forgejo\n/webhooks/gitea {\n  auth hmac {\n    provider gitea\n    secret env:GITEA_WEBHOOK_SECRET\n  }\n  pull { path /pull/gitea }\n}\n```\n\n## Pull API Calls\n\nAssume base URL `http://localhost:9443/pull/github` and token in `HOOKAIDO_PULL_TOKEN`.\n\n```bash\n# Dequeue\ncurl -sS -X POST \"http://localhost:9443/pull/github/dequeue\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"batch\":10,\"lease_ttl\":\"30s\",\"max_wait\":\"5s\"}'\n\n# Ack\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\"}'\n\n# Batch ack (v2.2.0+)\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_ids\":[\"lease_a\",\"lease_b\"]}'\n\n# Nack (requeue with delay)\ncurl -sS -X POST \"http://localhost:9443/pull/github/nack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\",\"delay\":\"5s\",\"dead\":false}'\n\n# Extend lease\ncurl -sS -X POST \"http://localhost:9443/pull/github/extend\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\",\"lease_ttl\":\"30s\"}'\n\n# Batch nack (v2.2.0+)\ncurl -sS -X POST \"http://localhost:9443/pull/github/nack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_ids\":[\"lease_a\",\"lease_b\"],\"delay\":\"5s\",\"dead\":false}'\n```\n\n## Optional gRPC Pull-Worker Mode (`v1.4.0+`)\n\nEnable gRPC pull-worker transport alongside HTTP pull:\n\n```hcl\npull_api {\n  listen :9443\n  grpc_listen :9943\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  pull { path /pull/github }\n}\n```\n\nUse gRPC workers with the same lease semantics and operation parity as Pull HTTP:\n\n- `Dequeue` -> `POST {endpoint}/dequeue`\n- `Ack` -> `POST {endpoint}/ack`\n- `Nack` -> `POST {endpoint}/nack`\n- `Extend` -> `POST {endpoint}/extend`\n\nNotes:\n\n- Worker gRPC reuses pull token auth and pull endpoint routing.\n- Keep `grpc_listen` on a dedicated internal listener; do not share ingress/pull/admin/metrics ports.\n- Worker lease operations are intentionally outside MCP scope.\n\n## Queue Backend Modes\n\n```hcl\n# Default durable mode\nqueue sqlite\n\n# Ephemeral development/testing mode\nqueue memory\n\n# Shared database mode (v2.2.0+)\nqueue postgres\n```\n\nPostgres runtime wiring:\n\n```bash\nexport HOOKAIDO_POSTGRES_DSN='postgres://user:pass@db.internal/hookaido?sslmode=require'\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\n```\n\n## Admin API Reads\n\n```bash\n# Health summary\ncurl -sS \"http://127.0.0.1:2019/healthz\"\n\n# Detailed diagnostics\ncurl -sS \"http://127.0.0.1:2019/healthz?details=1\"\n\n# Backlog trends\ncurl -sS \"http://127.0.0.1:2019/backlog/trends?window=1h&step=5m\"\n\n# Dead-letter queue\ncurl -sS \"http://127.0.0.1:2019/dlq?limit=50\"\n```\n\n## Admin API Mutations\n\nUse `X-Hookaido-Audit-Reason` and keep reasons actionable.\n\n```bash\n# Requeue DLQ items\ncurl -sS -X POST \"http://127.0.0.1:2019/dlq/requeue\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-Hookaido-Audit-Reason: retry-after-fix\" \\\n  -d '{\"ids\":[\"evt_1\",\"evt_2\"]}'\n\n# Delete DLQ items\ncurl -sS -X POST \"http://127.0.0.1:2019/dlq/delete\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-Hookaido-Audit-Reason: remove-invalid-payloads\" \\\n  -d '{\"ids\":[\"evt_3\"]}'\n```\n\n## MCP Role Patterns\n\n```bash\n# Read-only diagnostics\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\n\n# Queue mutation workflows\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db \\\n  --enable-mutations --role operate --principal ops@example.test\n\n# Full admin control (includes runtime operations)\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db \\\n  --enable-mutations --enable-runtime-control --role admin \\\n  --principal ops@example.test --pid-file ./hookaido.pid\n```\n\nFile v2.2.3:RELEASE_NOTES.md\n\n# Release Notes\n\n## GitHub Release Summary\n\nRecommended tag: `v2.2.1`\n\nBugfix-only update pinning to upstream Hookaido `v2.2.1`.\nUpstream fixes: dispatcher delivery logging, zero-target route warning, hot-reload for delivery config changes.\n\n## v2.2.1 - 2026-03-30\n\nBugfix-only update pinning to upstream Hookaido `v2.2.1`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.1`.\n- Upstream fixes: dispatcher delivery logging (previously silent), zero-target route warning, hot-reload for delivery config changes via `--watch`/SIGHUP.\n\n### Compatibility\n\nNo new features. All existing skill workflows remain unchanged.\n\n## v2.2.0 - 2026-03-28\n\nThis release updates the public Hookaido skill to upstream Hookaido `v2.2.0`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.0`.\n- Added `deliver exec` playbook for subprocess delivery (payload on stdin, exit-code retry semantics).\n- Added provider-compatible HMAC playbook for GitHub (`X-Hub-Signature-256`) and Gitea/Forgejo (`X-Gitea-Signature`).\n- Updated operations reference with exec delivery and provider-HMAC config examples.\n\n### Compatibility\n\nAdditive v2.2.0 coverage includes:\n\n- `deliver exec` for local script/binary execution with env-var metadata and exit-code retry semantics\n- `auth hmac { provider github }` / `auth hmac { provider gitea }` for native webhook signature verification\n- Custom outbound headers in deliver blocks with placeholder interpolation\n\nAll existing skill workflows remain unchanged.\n\n## v2.0.0 - 2026-03-09\n\nThis release updates the public Hookaido skill to upstream Hookaido `v2.0.0` and prepares the repository for distribution via its public GitHub URL.\n\n### Highlights\n\n- Pinned all binary installer actions to Hookaido `v2.0.0`.\n- Updated the fallback installer script with the official `v2.0.0` SHA256 checksums for macOS, Linux, and Windows on `amd64` and `arm64`.\n- Switched the skill homepage metadata to the public skill repository: `https://github.com/7schmiede/claw-skill-hookaido`.\n- Documented source-based installation from the public upstream repo: `go install github.com/nuetzliches/hookaido/cmd/hookaido@v2.0.0`.\n\n### Compatibility\n\nThis skill keeps the established inbound, outbound, and pull-based workflow as the default path.\nHookaido v2 capabilities are documented as additive options so existing skill usage does not receive breaking changes by default.\n\nAdditive v2 coverage includes:\n\n- `queue postgres` as an optional backend alongside the existing defaults\n- HTTP and gRPC pull-worker guidance\n- Batch `ack` and batch `nack` pull operations\n- `config validate --strict-secrets`\n- `verify-release` for public release verification\n\n### Documentation Updates\n\n- Refreshed [SKILL.md](SKILL.md) to reflect Hookaido v2.0.0 terminology and workflow guidance.\n- Expanded [references/operations.md](references/operations.md) with Postgres runtime examples, batch pull API calls, and release verification commands.\n- Added [README.md](README.md) so the repo is ready to be consumed directly as a public skill repository.\n\n### Notes\n\n- Upstream modular architecture changes in Hookaido v2.0.0 are treated as opt-in guidance in this skill rather than mandatory workflow changes.\n- The skill name now matches the repository folder name, which fixes skill validation in the current layout.\n\nFile v2.2.3:agents/openai.yaml\n\ninterface:\n  display_name: \"Hookaido Operator\"\n  short_description: \"Webhook/webhooks flows, queue ops, MCP, and gRPC-pull\"\n  default_prompt: \"Use this skill for Hookaido inbound/outbound webhook flows, queue triage, MCP operations, and HTTP/gRPC pull workers.\"\n\nArchive v2.2.2: 7 files, 11715 bytes\n\nFiles: agents/openai.yaml (262b), README.md (1008b), references/operations.md (7749b), RELEASE_NOTES.md (3049b), scripts/install_hookaido.sh (4705b), SKILL.md (11067b), _meta.json (127b)\n\nFile v2.2.2:SKILL.md\n\n---\nname: hookaido\nversion: \"2.2.2\"\ndescription: >-\n  Webhook infrastructure for receiving, queuing, and delivering webhooks.\n  Operate Hookaido webhook ingress, durable webhook queue (SQLite/Postgres),\n  webhook delivery (HTTP push, subprocess exec, pull API), webhook signature\n  verification (HMAC, GitHub webhooks, Gitea webhooks), dead-letter queue,\n  and webhook retry policies. Use when tasks involve webhook endpoint\n  configuration (Hookaidofile), webhook queue backends (sqlite, memory,\n  postgres), hookaido CLI (run, config fmt, config validate, mcp serve),\n  webhook consumption (dequeue/ack/nack/extend) over HTTP or gRPC, subprocess\n  webhook handlers (deliver exec), webhook provider HMAC (GitHub/Gitea/Stripe),\n  Admin API webhook backlog/DLQ triage, or production webhook hardening.\nmetadata:\n  openclaw:\n    homepage: https://github.com/7schmiede/claw-skill-hookaido\n    emoji: \"\\U0001FA9D\"\n    primaryEnv: HOOKAIDO_PULL_TOKEN\n    requires:\n      bins:\n        - hookaido\n      env:\n        - HOOKAIDO_PULL_TOKEN\n        - HOOKAIDO_INGRESS_SECRET\n    install:\n      - id: go-install\n        kind: go\n        package: github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.0\n        bins:\n          - hookaido\n      - id: download-darwin-amd64\n        kind: download\n        os:\n          - darwin\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_darwin_amd64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (macOS amd64)\n      - id: download-darwin-arm64\n        kind: download\n        os:\n          - darwin\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_darwin_arm64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (macOS arm64)\n      - id: download-linux-amd64\n        kind: download\n        os:\n          - linux\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_linux_amd64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (Linux amd64)\n      - id: download-linux-arm64\n        kind: download\n        os:\n          - linux\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_linux_arm64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (Linux arm64)\n      - id: download-windows-amd64\n        kind: download\n        os:\n          - win32\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_windows_amd64.zip\n        archive: zip\n        extract: true\n        targetDir: ~/.openclaw/tools/hookaido\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (Windows amd64)\n      - id: download-windows-arm64\n        kind: download\n        os:\n          - win32\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_windows_arm64.zip\n        archive: zip\n        extract: true\n        targetDir: ~/.openclaw/tools/hookaido\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (Windows arm64)\n---\n\n# Hookaido\n\n## Overview\n\nImplement and troubleshoot Hookaido with a config-first workflow: edit `Hookaidofile`, validate, run, exercise ingress/pull/exec flows, then diagnose queue health and DLQ behavior.\nTreat Hookaido v2.2.0's modular architecture as additive in this skill: keep the existing workflow intact by default, and opt into modules such as `postgres`, gRPC workers, subprocess delivery (`deliver exec`), or release verification only when they materially help the task.\nUse conservative, reversible changes and validate before runtime operations.\n\n## Workflow\n\n1. Confirm target topology: inbound+pull (HTTP or gRPC), push outbound, subprocess exec, or internal queue, plus the queue backend (`sqlite`, `memory`, or `postgres`).\n2. Choose runtime mode and ensure `hookaido` exists where tools execute.\n   - Host-binary mode: use the install action from `metadata.openclaw.install`.\n   - Host fallback: run `bash {baseDir}/scripts/install_hookaido.sh` (pinned `v2.2.0`, SHA256-verified).\n   - Public repo/source mode: use the public upstream repo `github.com/nuetzliches/hookaido` via `go install github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.0` when a source-based install is preferred.\n   - Docker-sandbox mode: use a sandbox image that already includes `hookaido` (preferred), or install inside sandbox via `agents.defaults.sandbox.docker.setupCommand`.\n   - Keep host install actions available as fallback and to satisfy `metadata.openclaw.requires.bins`.\n3. Inspect and update `Hookaidofile` minimally.\n4. Run format and validation before starting or reloading:\n   - `hookaido config fmt --config ./Hookaidofile`\n   - `hookaido config validate --config ./Hookaidofile`\n   - `hookaido config validate --config ./Hookaidofile --strict-secrets` when secret refs or Vault-backed config are involved.\n5. Start runtime and verify health:\n   - `hookaido run --config ./Hookaidofile --db ./.data/hookaido.db`\n   - `hookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"` when `queue postgres` is selected.\n   - `curl http://127.0.0.1:2019/healthz?details=1`\n6. Validate end-to-end behavior:\n   - ingress request accepted and queued\n   - consumer `dequeue`/`ack`/`nack`/`extend` path works (HTTP pull, batch `ack`/`nack`, plus gRPC pull when enabled)\n7. For incidents, inspect backlog and DLQ first, then mutate.\n\n## Task Playbooks\n\n### Configure Ingress and Pull Consumption\n\n1. Define a route with explicit auth and pull path (HTTP pull, optional gRPC pull worker listener).\n2. Keep secrets in env/file refs, never inline.\n3. Verify route and global pull auth are consistent.\n4. Test with a real webhook payload and a dequeue/ack cycle, using batch `ack`/`nack` when worker throughput matters.\n\nPrefer this baseline:\n\n```hcl\ningress {\n  listen :8080\n}\n\npull_api {\n  listen :9443\n  grpc_listen :9943 # optional gRPC pull-worker listener\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\n  pull { path /pull/github }\n}\n```\n\n### Configure Push Delivery\n\n1. Use push delivery only when inbound connectivity to the service is acceptable.\n2. Set timeout and retry policy explicitly.\n3. Validate downstream idempotency since delivery is at-least-once.\n\n```hcl\n/webhooks/stripe {\n  auth hmac env:STRIPE_SIGNING_SECRET\n  deliver \"https://billing.internal/stripe\" {\n    retry exponential max 8 base 2s cap 2m jitter 0.2\n    timeout 10s\n  }\n}\n```\n\n### Configure Subprocess Delivery (`deliver exec`)\n\n1. Use exec delivery when the target is a local script or binary, not an HTTP service.\n2. Payload is piped to stdin; metadata arrives as env vars (`HOOKAIDO_ROUTE`, `HOOKAIDO_EVENT_ID`, `HOOKAIDO_ATTEMPT`, etc.).\n3. Exit code determines retry behavior: `0` = ack, `1-125` = retry, `126`/`127` = immediate DLQ.\n4. `sign` directives are not supported with exec (compile error).\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  deliver exec \"/opt/hooks/deploy.sh\" {\n    timeout 30s\n    retry exponential max 3 base 1s cap 30s jitter 0.2\n    env DEPLOY_ENV production\n    env NOTIFY_URL {env.SLACK_WEBHOOK_URL}\n  }\n}\n```\n\n### Configure Provider-Compatible HMAC\n\n1. Use `provider github` or `provider gitea` for webhook providers that use their own signature format.\n2. Provider mode disables timestamp/nonce replay protection (providers do not send those headers).\n3. `signature_header`, `timestamp_header`, `nonce_header`, and `tolerance` are forbidden in provider mode (compile error).\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  pull { path /pull/github }\n}\n\n/webhooks/gitea {\n  auth hmac {\n    provider gitea\n    secret env:GITEA_WEBHOOK_SECRET\n  }\n  pull { path /pull/gitea }\n}\n```\n\n### Configure Queue Backends\n\n1. Default to `sqlite` unless the task explicitly needs ephemeral dev mode or shared Postgres storage.\n2. Treat `memory` and `postgres` as additive v2 modules, not replacements for existing sqlite workflows.\n3. When using `postgres`, document the DSN source and validate health plus backlog endpoints after startup.\n\nPrefer these patterns:\n\n```hcl\nqueue sqlite\n\nqueue memory\n\nqueue postgres\n```\n\n### Operate Queue and DLQ\n\n1. Start with health details and backlog endpoints.\n2. Inspect DLQ before requeue or delete.\n3. If requeueing many items, explain expected impact and rollback path.\n4. Require clear operator reason strings for mutating admin calls.\n\nUse:\n\n- `GET /healthz?details=1`\n- `GET /backlog/trends`\n- `GET /dlq`\n- `POST /dlq/requeue`\n- `POST /dlq/delete`\n\n### Use MCP Mode for AI Operations\n\n1. Default to `--role read` for diagnostics.\n2. Enable mutations only with explicit operator intent:\n   - `--enable-mutations --role operate --principal <identity>`\n3. Enable runtime control only for admin workflows:\n   - `--enable-runtime-control --role admin --pid-file <path>`\n4. Include `reason` for mutation calls and keep it specific.\n\n### Verify Public Releases\n\n1. Prefer official release assets from the public Hookaido repo.\n2. When supply-chain assurance matters, validate checksums, signature material, and provenance before rollout.\n3. Keep verification optional by default so existing skill flows do not become heavier unless the task requires it.\n\nUse:\n\n- `hookaido verify-release --checksums ./hookaido_v2.2.0_checksums.txt --require-provenance`\n\n## Validation Checklist\n\n- `hookaido config validate` returns success before runtime start/reload.\n- `hookaido config validate --strict-secrets` is used when secret refs, Vault, or public-release rollout validation matters.\n- Health endpoint is reachable and reports expected queue/backend state.\n- Pull consumer can `dequeue`, `ack`, `nack`, and `extend` with valid token (HTTP and optional gRPC transport), including batch `ack`/`nack` when enabled.\n- For push mode, retry/timeout behavior is explicitly configured.\n- For exec mode, handler script is executable, reads stdin, and uses exit codes correctly (0=ack, non-zero=retry, 126/127=DLQ).\n- For `queue postgres`, runtime is started with `--postgres-dsn` or `HOOKAIDO_POSTGRES_DSN`.\n- Any DLQ mutation is scoped, justified, and logged.\n\n## Safety Rules\n\n- Do not disable auth to \"make tests pass.\"\n- Do not suggest direct mutations before read-only diagnostics.\n- Treat queue operations as at-least-once; require idempotent handlers.\n- Keep secrets in `env:` or `file:` refs.\n\n## References\n\n- Read `references/operations.md` for command snippets and API payload templates.\n\nFile v2.2.2:README.md\n\n# hookaido\n\nPublic OpenClaw skill for [Hookaido](https://github.com/nuetzliches/hookaido) — webhook infrastructure that just works.\n\nRepository link for skill distribution:\n\n- `https://github.com/7schmiede/claw-skill-hookaido`\n\nUpstream Hookaido project:\n\n- `https://github.com/nuetzliches/hookaido`\n\nThis skill is pinned to Hookaido `v2.2.0` and keeps existing inbound/outbound/pull workflows as the default path.\nNew capabilities such as `deliver exec` (subprocess delivery), provider-compatible HMAC (GitHub/Gitea), `queue postgres`, gRPC pull workers, batch `ack`/`nack`, and release verification are documented as additive modules so existing usage does not receive breaking changes by default.\n\nMain files:\n\n- `SKILL.md` for skill metadata and operating guidance\n- `references/operations.md` for install, runtime, and API command examples\n- `scripts/install_hookaido.sh` for pinned release-binary installation with SHA256 verification\n- `RELEASE_NOTES.md` for the current public skill release summary\n\nFile v2.2.2:_meta.json\n\n{\n  \"ownerId\": \"kn70n9zjjpmw2dg19a8n5w8bm1813vkf\",\n  \"slug\": \"hookaido\",\n  \"version\": \"2.2.2\",\n  \"publishedAt\": 1774707114652\n}\n\nFile v2.2.2:references/operations.md\n\n# Hookaido Operations Reference\n\nUse this file for concrete command syntax and request payloads.\n\n## Install Hookaido\n\nOpenClaw supports two runtime variants.\n\nPublic repositories:\n\n- Upstream project: `https://github.com/nuetzliches/hookaido`\n- Public skill repo: `https://github.com/7schmiede/claw-skill-hookaido`\n\n### Variant A: Host Binary (Gateway/Host)\n\n- Use one of the skill installer actions from `metadata.openclaw.install` (platform + architecture specific download).\n- Choose the artifact that matches your host architecture (`amd64` or `arm64`).\n- The OpenClaw download URLs are pinned to Hookaido `v2.2.0`.\n- macOS/Linux installers extract to `~/.local/bin` (with `stripComponents: 1`).\n- Windows installers extract to `~/.openclaw/tools/hookaido`.\n\nDirect CLI fallback:\n\n```bash\ngo install github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.0\n```\n\nRelease-binary fallback from this skill folder:\n\n```bash\nbash {baseDir}/scripts/install_hookaido.sh\n```\n\nThe fallback installer is hardened:\n\n- Defaults to pinned `v2.2.0` (no dynamic `latest` lookup).\n- Verifies SHA256 of the downloaded release artifact before extraction/install.\n\nOptional pins/overrides for the installer script:\n\n```bash\n# Default pinned install, custom location\nHOOKAIDO_INSTALL_DIR=\"$HOME/bin\" bash {baseDir}/scripts/install_hookaido.sh\n\n# Non-default release requires explicit checksum\nHOOKAIDO_VERSION=v2.0.1 \\\nHOOKAIDO_SHA256=\"<artifact-sha256>\" \\\nbash {baseDir}/scripts/install_hookaido.sh\n```\n\n### Variant B: Docker Sandbox\n\n- OpenClaw supports Docker sandbox mode via `sandboxing.enabled: true` and `sandboxing.type: docker`.\n- Preferred: provide a custom sandbox image with `hookaido` preinstalled, and pin the image by immutable digest.\n- Optional: use `agents.defaults.sandbox.docker.setupCommand` to install `hookaido` inside the container at startup.\n- Keep `metadata.openclaw.install` as fallback and for `metadata.openclaw.requires.bins` checks on the host.\n\n## Core CLI Commands\n\n```bash\n# Validate and format config\nhookaido config fmt --config ./Hookaidofile\nhookaido config validate --config ./Hookaidofile\nhookaido config validate --config ./Hookaidofile --strict-secrets\n\n# Start runtime\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db\n\n# Start runtime with Postgres queue backend\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\n\n# Start runtime with live config watch\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db --watch\n\n# Start MCP server (read-only)\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\n\n# Verify a public release bundle before rollout\nhookaido verify-release \\\n  --checksums ./hookaido_v2.2.0_checksums.txt \\\n  --public-key ./hookaido_v2.2.0_checksums.txt.pub.pem \\\n  --require-provenance\n```\n\n## Minimal Pull-Mode Config\n\n```hcl\ningress {\n  listen :8080\n}\n\npull_api {\n  listen :9443\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\n  pull { path /pull/github }\n}\n```\n\n## Exec Delivery Config (v2.2.0+)\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  deliver exec \"/opt/hooks/deploy.sh\" {\n    timeout 30s\n    retry exponential max 3 base 1s cap 30s jitter 0.2\n    env DEPLOY_ENV production\n  }\n}\n```\n\nExit codes: `0` = ack, `75`/`1-125` = retry, `126`/`127` = immediate DLQ.\nMetadata env vars: `HOOKAIDO_ROUTE`, `HOOKAIDO_EVENT_ID`, `HOOKAIDO_CONTENT_TYPE`, `HOOKAIDO_ATTEMPT`, `HOOKAIDO_HEADER_*`.\n\n## Provider-Compatible HMAC Config (v2.2.0+)\n\n```hcl\n# GitHub\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  pull { path /pull/github }\n}\n\n# Gitea / Forgejo\n/webhooks/gitea {\n  auth hmac {\n    provider gitea\n    secret env:GITEA_WEBHOOK_SECRET\n  }\n  pull { path /pull/gitea }\n}\n```\n\n## Pull API Calls\n\nAssume base URL `http://localhost:9443/pull/github` and token in `HOOKAIDO_PULL_TOKEN`.\n\n```bash\n# Dequeue\ncurl -sS -X POST \"http://localhost:9443/pull/github/dequeue\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"batch\":10,\"lease_ttl\":\"30s\",\"max_wait\":\"5s\"}'\n\n# Ack\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\"}'\n\n# Batch ack (v2.2.0+)\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_ids\":[\"lease_a\",\"lease_b\"]}'\n\n# Nack (requeue with delay)\ncurl -sS -X POST \"http://localhost:9443/pull/github/nack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\",\"delay\":\"5s\",\"dead\":false}'\n\n# Extend lease\ncurl -sS -X POST \"http://localhost:9443/pull/github/extend\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\",\"lease_ttl\":\"30s\"}'\n\n# Batch nack (v2.2.0+)\ncurl -sS -X POST \"http://localhost:9443/pull/github/nack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_ids\":[\"lease_a\",\"lease_b\"],\"delay\":\"5s\",\"dead\":false}'\n```\n\n## Optional gRPC Pull-Worker Mode (`v1.4.0+`)\n\nEnable gRPC pull-worker transport alongside HTTP pull:\n\n```hcl\npull_api {\n  listen :9443\n  grpc_listen :9943\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  pull { path /pull/github }\n}\n```\n\nUse gRPC workers with the same lease semantics and operation parity as Pull HTTP:\n\n- `Dequeue` -> `POST {endpoint}/dequeue`\n- `Ack` -> `POST {endpoint}/ack`\n- `Nack` -> `POST {endpoint}/nack`\n- `Extend` -> `POST {endpoint}/extend`\n\nNotes:\n\n- Worker gRPC reuses pull token auth and pull endpoint routing.\n- Keep `grpc_listen` on a dedicated internal listener; do not share ingress/pull/admin/metrics ports.\n- Worker lease operations are intentionally outside MCP scope.\n\n## Queue Backend Modes\n\n```hcl\n# Default durable mode\nqueue sqlite\n\n# Ephemeral development/testing mode\nqueue memory\n\n# Shared database mode (v2.2.0+)\nqueue postgres\n```\n\nPostgres runtime wiring:\n\n```bash\nexport HOOKAIDO_POSTGRES_DSN='postgres://user:pass@db.internal/hookaido?sslmode=require'\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\n```\n\n## Admin API Reads\n\n```bash\n# Health summary\ncurl -sS \"http://127.0.0.1:2019/healthz\"\n\n# Detailed diagnostics\ncurl -sS \"http://127.0.0.1:2019/healthz?details=1\"\n\n# Backlog trends\ncurl -sS \"http://127.0.0.1:2019/backlog/trends?window=1h&step=5m\"\n\n# Dead-letter queue\ncurl -sS \"http://127.0.0.1:2019/dlq?limit=50\"\n```\n\n## Admin API Mutations\n\nUse `X-Hookaido-Audit-Reason` and keep reasons actionable.\n\n```bash\n# Requeue DLQ items\ncurl -sS -X POST \"http://127.0.0.1:2019/dlq/requeue\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-Hookaido-Audit-Reason: retry-after-fix\" \\\n  -d '{\"ids\":[\"evt_1\",\"evt_2\"]}'\n\n# Delete DLQ items\ncurl -sS -X POST \"http://127.0.0.1:2019/dlq/delete\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-Hookaido-Audit-Reason: remove-invalid-payloads\" \\\n  -d '{\"ids\":[\"evt_3\"]}'\n```\n\n## MCP Role Patterns\n\n```bash\n# Read-only diagnostics\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\n\n# Queue mutation workflows\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db \\\n  --enable-mutations --role operate --principal ops@example.test\n\n# Full admin control (includes runtime operations)\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db \\\n  --enable-mutations --enable-runtime-control --role admin \\\n  --principal ops@example.test --pid-file ./hookaido.pid\n```\n\nFile v2.2.2:RELEASE_NOTES.md\n\n# Release Notes\n\n## GitHub Release Summary\n\nRecommended tag: `v2.2.0`\n\nPublic Hookaido skill refresh for upstream `v2.2.0`.\nThis update pins installer assets and checksums to Hookaido v2.2.0, adds subprocess delivery (`deliver exec`) and provider-compatible HMAC (GitHub/Gitea) as new skill playbooks, and updates all version references.\n\n## v2.2.0 - 2026-03-28\n\nThis release updates the public Hookaido skill to upstream Hookaido `v2.2.0`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.0`.\n- Added `deliver exec` playbook for subprocess delivery (payload on stdin, exit-code retry semantics).\n- Added provider-compatible HMAC playbook for GitHub (`X-Hub-Signature-256`) and Gitea/Forgejo (`X-Gitea-Signature`).\n- Updated operations reference with exec delivery and provider-HMAC config examples.\n\n### Compatibility\n\nAdditive v2.2.0 coverage includes:\n\n- `deliver exec` for local script/binary execution with env-var metadata and exit-code retry semantics\n- `auth hmac { provider github }` / `auth hmac { provider gitea }` for native webhook signature verification\n- Custom outbound headers in deliver blocks with placeholder interpolation\n\nAll existing skill workflows remain unchanged.\n\n## v2.0.0 - 2026-03-09\n\nThis release updates the public Hookaido skill to upstream Hookaido `v2.0.0` and prepares the repository for distribution via its public GitHub URL.\n\n### Highlights\n\n- Pinned all binary installer actions to Hookaido `v2.0.0`.\n- Updated the fallback installer script with the official `v2.0.0` SHA256 checksums for macOS, Linux, and Windows on `amd64` and `arm64`.\n- Switched the skill homepage metadata to the public skill repository: `https://github.com/7schmiede/claw-skill-hookaido`.\n- Documented source-based installation from the public upstream repo: `go install github.com/nuetzliches/hookaido/cmd/hookaido@v2.0.0`.\n\n### Compatibility\n\nThis skill keeps the established inbound, outbound, and pull-based workflow as the default path.\nHookaido v2 capabilities are documented as additive options so existing skill usage does not receive breaking changes by default.\n\nAdditive v2 coverage includes:\n\n- `queue postgres` as an optional backend alongside the existing defaults\n- HTTP and gRPC pull-worker guidance\n- Batch `ack` and batch `nack` pull operations\n- `config validate --strict-secrets`\n- `verify-release` for public release verification\n\n### Documentation Updates\n\n- Refreshed [SKILL.md](SKILL.md) to reflect Hookaido v2.0.0 terminology and workflow guidance.\n- Expanded [references/operations.md](references/operations.md) with Postgres runtime examples, batch pull API calls, and release verification commands.\n- Added [README.md](README.md) so the repo is ready to be consumed directly as a public skill repository.\n\n### Notes\n\n- Upstream modular architecture changes in Hookaido v2.0.0 are treated as opt-in guidance in this skill rather than mandatory workflow changes.\n- The skill name now matches the repository folder name, which fixes skill validation in the current layout.\n\nFile v2.2.2:agents/openai.yaml\n\ninterface:\n  display_name: \"Hookaido Operator\"\n  short_description: \"Webhook/webhooks flows, queue ops, MCP, and gRPC-pull\"\n  default_prompt: \"Use this skill for Hookaido inbound/outbound webhook flows, queue triage, MCP operations, and HTTP/gRPC pull workers.\"\n\nArchive v2.2.1: 7 files, 11711 bytes\n\nFiles: agents/openai.yaml (262b), README.md (1008b), references/operations.md (7749b), RELEASE_NOTES.md (3049b), scripts/install_hookaido.sh (4705b), SKILL.md (11026b), _meta.json (127b)\n\nFile v2.2.1:SKILL.md\n\n---\nname: hookaido\nversion: \"2.2.1\"\ndescription: >-\n  Receive incoming webhooks from external services and trigger automations,\n  integrations, and event-driven workflows. Operate inbound/outbound/internal\n  webhook flows with Hookaido v2, queue triage, MCP workflows, release\n  verification, subprocess delivery (deliver exec), and HTTP/gRPC pull workers.\n  Use when tasks involve Hookaidofile authoring, queue backend selection\n  (sqlite, memory, postgres), hookaido CLI commands (run, config fmt, config\n  validate, mcp serve), pull operations (dequeue/ack/nack/extend) over HTTP or\n  gRPC, subprocess execution via deliver exec, provider-compatible HMAC\n  (GitHub/Gitea), Admin API backlog/DLQ handling, or production hardening for\n  ingress and delivery.\nmetadata:\n  openclaw:\n    homepage: https://github.com/7schmiede/claw-skill-hookaido\n    emoji: \"\\U0001FA9D\"\n    primaryEnv: HOOKAIDO_PULL_TOKEN\n    requires:\n      bins:\n        - hookaido\n      env:\n        - HOOKAIDO_PULL_TOKEN\n        - HOOKAIDO_INGRESS_SECRET\n    install:\n      - id: go-install\n        kind: go\n        package: github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.0\n        bins:\n          - hookaido\n      - id: download-darwin-amd64\n        kind: download\n        os:\n          - darwin\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_darwin_amd64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (macOS amd64)\n      - id: download-darwin-arm64\n        kind: download\n        os:\n          - darwin\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_darwin_arm64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (macOS arm64)\n      - id: download-linux-amd64\n        kind: download\n        os:\n          - linux\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_linux_amd64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (Linux amd64)\n      - id: download-linux-arm64\n        kind: download\n        os:\n          - linux\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_linux_arm64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (Linux arm64)\n      - id: download-windows-amd64\n        kind: download\n        os:\n          - win32\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_windows_amd64.zip\n        archive: zip\n        extract: true\n        targetDir: ~/.openclaw/tools/hookaido\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (Windows amd64)\n      - id: download-windows-arm64\n        kind: download\n        os:\n          - win32\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.2.0/hookaido_v2.2.0_windows_arm64.zip\n        archive: zip\n        extract: true\n        targetDir: ~/.openclaw/tools/hookaido\n        bins:\n          - hookaido\n        label: Download hookaido v2.2.0 (Windows arm64)\n---\n\n# Hookaido\n\n## Overview\n\nImplement and troubleshoot Hookaido with a config-first workflow: edit `Hookaidofile`, validate, run, exercise ingress/pull/exec flows, then diagnose queue health and DLQ behavior.\nTreat Hookaido v2.2.0's modular architecture as additive in this skill: keep the existing workflow intact by default, and opt into modules such as `postgres`, gRPC workers, subprocess delivery (`deliver exec`), or release verification only when they materially help the task.\nUse conservative, reversible changes and validate before runtime operations.\n\n## Workflow\n\n1. Confirm target topology: inbound+pull (HTTP or gRPC), push outbound, subprocess exec, or internal queue, plus the queue backend (`sqlite`, `memory`, or `postgres`).\n2. Choose runtime mode and ensure `hookaido` exists where tools execute.\n   - Host-binary mode: use the install action from `metadata.openclaw.install`.\n   - Host fallback: run `bash {baseDir}/scripts/install_hookaido.sh` (pinned `v2.2.0`, SHA256-verified).\n   - Public repo/source mode: use the public upstream repo `github.com/nuetzliches/hookaido` via `go install github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.0` when a source-based install is preferred.\n   - Docker-sandbox mode: use a sandbox image that already includes `hookaido` (preferred), or install inside sandbox via `agents.defaults.sandbox.docker.setupCommand`.\n   - Keep host install actions available as fallback and to satisfy `metadata.openclaw.requires.bins`.\n3. Inspect and update `Hookaidofile` minimally.\n4. Run format and validation before starting or reloading:\n   - `hookaido config fmt --config ./Hookaidofile`\n   - `hookaido config validate --config ./Hookaidofile`\n   - `hookaido config validate --config ./Hookaidofile --strict-secrets` when secret refs or Vault-backed config are involved.\n5. Start runtime and verify health:\n   - `hookaido run --config ./Hookaidofile --db ./.data/hookaido.db`\n   - `hookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"` when `queue postgres` is selected.\n   - `curl http://127.0.0.1:2019/healthz?details=1`\n6. Validate end-to-end behavior:\n   - ingress request accepted and queued\n   - consumer `dequeue`/`ack`/`nack`/`extend` path works (HTTP pull, batch `ack`/`nack`, plus gRPC pull when enabled)\n7. For incidents, inspect backlog and DLQ first, then mutate.\n\n## Task Playbooks\n\n### Configure Ingress and Pull Consumption\n\n1. Define a route with explicit auth and pull path (HTTP pull, optional gRPC pull worker listener).\n2. Keep secrets in env/file refs, never inline.\n3. Verify route and global pull auth are consistent.\n4. Test with a real webhook payload and a dequeue/ack cycle, using batch `ack`/`nack` when worker throughput matters.\n\nPrefer this baseline:\n\n```hcl\ningress {\n  listen :8080\n}\n\npull_api {\n  listen :9443\n  grpc_listen :9943 # optional gRPC pull-worker listener\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\n  pull { path /pull/github }\n}\n```\n\n### Configure Push Delivery\n\n1. Use push delivery only when inbound connectivity to the service is acceptable.\n2. Set timeout and retry policy explicitly.\n3. Validate downstream idempotency since delivery is at-least-once.\n\n```hcl\n/webhooks/stripe {\n  auth hmac env:STRIPE_SIGNING_SECRET\n  deliver \"https://billing.internal/stripe\" {\n    retry exponential max 8 base 2s cap 2m jitter 0.2\n    timeout 10s\n  }\n}\n```\n\n### Configure Subprocess Delivery (`deliver exec`)\n\n1. Use exec delivery when the target is a local script or binary, not an HTTP service.\n2. Payload is piped to stdin; metadata arrives as env vars (`HOOKAIDO_ROUTE`, `HOOKAIDO_EVENT_ID`, `HOOKAIDO_ATTEMPT`, etc.).\n3. Exit code determines retry behavior: `0` = ack, `1-125` = retry, `126`/`127` = immediate DLQ.\n4. `sign` directives are not supported with exec (compile error).\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  deliver exec \"/opt/hooks/deploy.sh\" {\n    timeout 30s\n    retry exponential max 3 base 1s cap 30s jitter 0.2\n    env DEPLOY_ENV production\n    env NOTIFY_URL {env.SLACK_WEBHOOK_URL}\n  }\n}\n```\n\n### Configure Provider-Compatible HMAC\n\n1. Use `provider github` or `provider gitea` for webhook providers that use their own signature format.\n2. Provider mode disables timestamp/nonce replay protection (providers do not send those headers).\n3. `signature_header`, `timestamp_header`, `nonce_header`, and `tolerance` are forbidden in provider mode (compile error).\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  pull { path /pull/github }\n}\n\n/webhooks/gitea {\n  auth hmac {\n    provider gitea\n    secret env:GITEA_WEBHOOK_SECRET\n  }\n  pull { path /pull/gitea }\n}\n```\n\n### Configure Queue Backends\n\n1. Default to `sqlite` unless the task explicitly needs ephemeral dev mode or shared Postgres storage.\n2. Treat `memory` and `postgres` as additive v2 modules, not replacements for existing sqlite workflows.\n3. When using `postgres`, document the DSN source and validate health plus backlog endpoints after startup.\n\nPrefer these patterns:\n\n```hcl\nqueue sqlite\n\nqueue memory\n\nqueue postgres\n```\n\n### Operate Queue and DLQ\n\n1. Start with health details and backlog endpoints.\n2. Inspect DLQ before requeue or delete.\n3. If requeueing many items, explain expected impact and rollback path.\n4. Require clear operator reason strings for mutating admin calls.\n\nUse:\n\n- `GET /healthz?details=1`\n- `GET /backlog/trends`\n- `GET /dlq`\n- `POST /dlq/requeue`\n- `POST /dlq/delete`\n\n### Use MCP Mode for AI Operations\n\n1. Default to `--role read` for diagnostics.\n2. Enable mutations only with explicit operator intent:\n   - `--enable-mutations --role operate --principal <identity>`\n3. Enable runtime control only for admin workflows:\n   - `--enable-runtime-control --role admin --pid-file <path>`\n4. Include `reason` for mutation calls and keep it specific.\n\n### Verify Public Releases\n\n1. Prefer official release assets from the public Hookaido repo.\n2. When supply-chain assurance matters, validate checksums, signature material, and provenance before rollout.\n3. Keep verification optional by default so existing skill flows do not become heavier unless the task requires it.\n\nUse:\n\n- `hookaido verify-release --checksums ./hookaido_v2.2.0_checksums.txt --require-provenance`\n\n## Validation Checklist\n\n- `hookaido config validate` returns success before runtime start/reload.\n- `hookaido config validate --strict-secrets` is used when secret refs, Vault, or public-release rollout validation matters.\n- Health endpoint is reachable and reports expected queue/backend state.\n- Pull consumer can `dequeue`, `ack`, `nack`, and `extend` with valid token (HTTP and optional gRPC transport), including batch `ack`/`nack` when enabled.\n- For push mode, retry/timeout behavior is explicitly configured.\n- For exec mode, handler script is executable, reads stdin, and uses exit codes correctly (0=ack, non-zero=retry, 126/127=DLQ).\n- For `queue postgres`, runtime is started with `--postgres-dsn` or `HOOKAIDO_POSTGRES_DSN`.\n- Any DLQ mutation is scoped, justified, and logged.\n\n## Safety Rules\n\n- Do not disable auth to \"make tests pass.\"\n- Do not suggest direct mutations before read-only diagnostics.\n- Treat queue operations as at-least-once; require idempotent handlers.\n- Keep secrets in `env:` or `file:` refs.\n\n## References\n\n- Read `references/operations.md` for command snippets and API payload templates.\n\nFile v2.2.1:README.md\n\n# hookaido\n\nPublic OpenClaw skill for [Hookaido](https://github.com/nuetzliches/hookaido) — webhook infrastructure that just works.\n\nRepository link for skill distribution:\n\n- `https://github.com/7schmiede/claw-skill-hookaido`\n\nUpstream Hookaido project:\n\n- `https://github.com/nuetzliches/hookaido`\n\nThis skill is pinned to Hookaido `v2.2.0` and keeps existing inbound/outbound/pull workflows as the default path.\nNew capabilities such as `deliver exec` (subprocess delivery), provider-compatible HMAC (GitHub/Gitea), `queue postgres`, gRPC pull workers, batch `ack`/`nack`, and release verification are documented as additive modules so existing usage does not receive breaking changes by default.\n\nMain files:\n\n- `SKILL.md` for skill metadata and operating guidance\n- `references/operations.md` for install, runtime, and API command examples\n- `scripts/install_hookaido.sh` for pinned release-binary installation with SHA256 verification\n- `RELEASE_NOTES.md` for the current public skill release summary\n\nFile v2.2.1:_meta.json\n\n{\n  \"ownerId\": \"kn70n9zjjpmw2dg19a8n5w8bm1813vkf\",\n  \"slug\": \"hookaido\",\n  \"version\": \"2.2.1\",\n  \"publishedAt\": 1774706996346\n}\n\nFile v2.2.1:references/operations.md\n\n# Hookaido Operations Reference\n\nUse this file for concrete command syntax and request payloads.\n\n## Install Hookaido\n\nOpenClaw supports two runtime variants.\n\nPublic repositories:\n\n- Upstream project: `https://github.com/nuetzliches/hookaido`\n- Public skill repo: `https://github.com/7schmiede/claw-skill-hookaido`\n\n### Variant A: Host Binary (Gateway/Host)\n\n- Use one of the skill installer actions from `metadata.openclaw.install` (platform + architecture specific download).\n- Choose the artifact that matches your host architecture (`amd64` or `arm64`).\n- The OpenClaw download URLs are pinned to Hookaido `v2.2.0`.\n- macOS/Linux installers extract to `~/.local/bin` (with `stripComponents: 1`).\n- Windows installers extract to `~/.openclaw/tools/hookaido`.\n\nDirect CLI fallback:\n\n```bash\ngo install github.com/nuetzliches/hookaido/cmd/hookaido@v2.2.0\n```\n\nRelease-binary fallback from this skill folder:\n\n```bash\nbash {baseDir}/scripts/install_hookaido.sh\n```\n\nThe fallback installer is hardened:\n\n- Defaults to pinned `v2.2.0` (no dynamic `latest` lookup).\n- Verifies SHA256 of the downloaded release artifact before extraction/install.\n\nOptional pins/overrides for the installer script:\n\n```bash\n# Default pinned install, custom location\nHOOKAIDO_INSTALL_DIR=\"$HOME/bin\" bash {baseDir}/scripts/install_hookaido.sh\n\n# Non-default release requires explicit checksum\nHOOKAIDO_VERSION=v2.0.1 \\\nHOOKAIDO_SHA256=\"<artifact-sha256>\" \\\nbash {baseDir}/scripts/install_hookaido.sh\n```\n\n### Variant B: Docker Sandbox\n\n- OpenClaw supports Docker sandbox mode via `sandboxing.enabled: true` and `sandboxing.type: docker`.\n- Preferred: provide a custom sandbox image with `hookaido` preinstalled, and pin the image by immutable digest.\n- Optional: use `agents.defaults.sandbox.docker.setupCommand` to install `hookaido` inside the container at startup.\n- Keep `metadata.openclaw.install` as fallback and for `metadata.openclaw.requires.bins` checks on the host.\n\n## Core CLI Commands\n\n```bash\n# Validate and format config\nhookaido config fmt --config ./Hookaidofile\nhookaido config validate --config ./Hookaidofile\nhookaido config validate --config ./Hookaidofile --strict-secrets\n\n# Start runtime\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db\n\n# Start runtime with Postgres queue backend\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\n\n# Start runtime with live config watch\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db --watch\n\n# Start MCP server (read-only)\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\n\n# Verify a public release bundle before rollout\nhookaido verify-release \\\n  --checksums ./hookaido_v2.2.0_checksums.txt \\\n  --public-key ./hookaido_v2.2.0_checksums.txt.pub.pem \\\n  --require-provenance\n```\n\n## Minimal Pull-Mode Config\n\n```hcl\ningress {\n  listen :8080\n}\n\npull_api {\n  listen :9443\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\n  pull { path /pull/github }\n}\n```\n\n## Exec Delivery Config (v2.2.0+)\n\n```hcl\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  deliver exec \"/opt/hooks/deploy.sh\" {\n    timeout 30s\n    retry exponential max 3 base 1s cap 30s jitter 0.2\n    env DEPLOY_ENV production\n  }\n}\n```\n\nExit codes: `0` = ack, `75`/`1-125` = retry, `126`/`127` = immediate DLQ.\nMetadata env vars: `HOOKAIDO_ROUTE`, `HOOKAIDO_EVENT_ID`, `HOOKAIDO_CONTENT_TYPE`, `HOOKAIDO_ATTEMPT`, `HOOKAIDO_HEADER_*`.\n\n## Provider-Compatible HMAC Config (v2.2.0+)\n\n```hcl\n# GitHub\n/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  pull { path /pull/github }\n}\n\n# Gitea / Forgejo\n/webhooks/gitea {\n  auth hmac {\n    provider gitea\n    secret env:GITEA_WEBHOOK_SECRET\n  }\n  pull { path /pull/gitea }\n}\n```\n\n## Pull API Calls\n\nAssume base URL `http://localhost:9443/pull/github` and token in `HOOKAIDO_PULL_TOKEN`.\n\n```bash\n# Dequeue\ncurl -sS -X POST \"http://localhost:9443/pull/github/dequeue\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"batch\":10,\"lease_ttl\":\"30s\",\"max_wait\":\"5s\"}'\n\n# Ack\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\"}'\n\n# Batch ack (v2.2.0+)\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_ids\":[\"lease_a\",\"lease_b\"]}'\n\n# Nack (requeue with delay)\ncurl -sS -X POST \"http://localhost:9443/pull/github/nack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\",\"delay\":\"5s\",\"dead\":false}'\n\n# Extend lease\ncurl -sS -X POST \"http://localhost:9443/pull/github/extend\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\",\"lease_ttl\":\"30s\"}'\n\n# Batch nack (v2.2.0+)\ncurl -sS -X POST \"http://localhost:9443/pull/github/nack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_ids\":[\"lease_a\",\"lease_b\"],\"delay\":\"5s\",\"dead\":false}'\n```\n\n## Optional gRPC Pull-Worker Mode (`v1.4.0+`)\n\nEnable gRPC pull-worker transport alongside HTTP pull:\n\n```hcl\npull_api {\n  listen :9443\n  grpc_listen :9943\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  pull { path /pull/github }\n}\n```\n\nUse gRPC workers with the same lease semantics and operation parity as Pull HTTP:\n\n- `Dequeue` -> `POST {endpoint}/dequeue`\n- `Ack` -> `POST {endpoint}/ack`\n- `Nack` -> `POST {endpoint}/nack`\n- `Extend` -> `POST {endpoint}/extend`\n\nNotes:\n\n- Worker gRPC reuses pull token auth and pull endpoint routing.\n- Keep `grpc_listen` on a dedicated internal listener; do not share ingress/pull/admin/metrics ports.\n- Worker lease operations are intentionally outside MCP scope.\n\n## Queue Backend Modes\n\n```hcl\n# Default durable mode\nqueue sqlite\n\n# Ephemeral development/testing mode\nqueue memory\n\n# Shared database mode (v2.2.0+)\nqueue postgres\n```\n\nPostgres runtime wiring:\n\n```bash\nexport HOOKAIDO_POSTGRES_DSN='postgres://user:pass@db.internal/hookaido?sslmode=require'\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\n```\n\n## Admin API Reads\n\n```bash\n# Health summary\ncurl -sS \"http://127.0.0.1:2019/healthz\"\n\n# Detailed diagnostics\ncurl -sS \"http://127.0.0.1:2019/healthz?details=1\"\n\n# Backlog trends\ncurl -sS \"http://127.0.0.1:2019/backlog/trends?window=1h&step=5m\"\n\n# Dead-letter queue\ncurl -sS \"http://127.0.0.1:2019/dlq?limit=50\"\n```\n\n## Admin API Mutations\n\nUse `X-Hookaido-Audit-Reason` and keep reasons actionable.\n\n```bash\n# Requeue DLQ items\ncurl -sS -X POST \"http://127.0.0.1:2019/dlq/requeue\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-Hookaido-Audit-Reason: retry-after-fix\" \\\n  -d '{\"ids\":[\"evt_1\",\"evt_2\"]}'\n\n# Delete DLQ items\ncurl -sS -X POST \"http://127.0.0.1:2019/dlq/delete\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-Hookaido-Audit-Reason: remove-invalid-payloads\" \\\n  -d '{\"ids\":[\"evt_3\"]}'\n```\n\n## MCP Role Patterns\n\n```bash\n# Read-only diagnostics\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\n\n# Queue mutation workflows\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db \\\n  --enable-mutations --role operate --principal ops@example.test\n\n# Full admin control (includes runtime operations)\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db \\\n  --enable-mutations --enable-runtime-control --role admin \\\n  --principal ops@example.test --pid-file ./hookaido.pid\n```\n\nFile v2.2.1:RELEASE_NOTES.md\n\n# Release Notes\n\n## GitHub Release Summary\n\nRecommended tag: `v2.2.0`\n\nPublic Hookaido skill refresh for upstream `v2.2.0`.\nThis update pins installer assets and checksums to Hookaido v2.2.0, adds subprocess delivery (`deliver exec`) and provider-compatible HMAC (GitHub/Gitea) as new skill playbooks, and updates all version references.\n\n## v2.2.0 - 2026-03-28\n\nThis release updates the public Hookaido skill to upstream Hookaido `v2.2.0`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.0`.\n- Added `deliver exec` playbook for subprocess delivery (payload on stdin, exit-code retry semantics).\n- Added provider-compatible HMAC playbook for GitHub (`X-Hub-Signature-256`) and Gitea/Forgejo (`X-Gitea-Signature`).\n- Updated operations reference with exec delivery and provider-HMAC config examples.\n\n### Compatibility\n\nAdditive v2.2.0 coverage includes:\n\n- `deliver exec` for local script/binary execution with env-var metadata and exit-code retry semantics\n- `auth hmac { provider github }` / `auth hmac { provider gitea }` for native webhook signature verification\n- Custom outbound headers in deliver blocks with placeholder interpolation\n\nAll existing skill workflows remain unchanged.\n\n## v2.0.0 - 2026-03-09\n\nThis release updates the public Hookaido skill to upstream Hookaido `v2.0.0` and prepares the repository for distribution via its public GitHub URL.\n\n### Highlights\n\n- Pinned all binary installer actions to Hookaido `v2.0.0`.\n- Updated the fallback installer script with the official `v2.0.0` SHA256 checksums for macOS, Linux, and Windows on `amd64` and `arm64`.\n- Switched the skill homepage metadata to the public skill repository: `https://github.com/7schmiede/claw-skill-hookaido`.\n- Documented source-based installation from the public upstream repo: `go install github.com/nuetzliches/hookaido/cmd/hookaido@v2.0.0`.\n\n### Compatibility\n\nThis skill keeps the established inbound, outbound, and pull-based workflow as the default path.\nHookaido v2 capabilities are documented as additive options so existing skill usage does not receive breaking changes by default.\n\nAdditive v2 coverage includes:\n\n- `queue postgres` as an optional backend alongside the existing defaults\n- HTTP and gRPC pull-worker guidance\n- Batch `ack` and batch `nack` pull operations\n- `config validate --strict-secrets`\n- `verify-release` for public release verification\n\n### Documentation Updates\n\n- Refreshed [SKILL.md](SKILL.md) to reflect Hookaido v2.0.0 terminology and workflow guidance.\n- Expanded [references/operations.md](references/operations.md) with Postgres runtime examples, batch pull API calls, and release verification commands.\n- Added [README.md](README.md) so the repo is ready to be consumed directly as a public skill repository.\n\n### Notes\n\n- Upstream modular architecture changes in Hookaido v2.0.0 are treated as opt-in guidance in this skill rather than mandatory workflow changes.\n- The skill name now matches the repository folder name, which fixes skill validation in the current layout.\n\nFile v2.2.1:agents/openai.yaml\n\ninterface:\n  display_name: \"Hookaido Operator\"\n  short_description: \"Webhook/webhooks flows, queue ops, MCP, and gRPC-pull\"\n  default_prompt: \"Use this skill for Hookaido inbound/outbound webhook flows, queue triage, MCP operations, and HTTP/gRPC pull workers.\"\n\nArchive v2.0.1: 7 files, 10409 bytes\n\nFiles: agents/openai.yaml (266b), README.md (888b), references/operations.md (7172b), RELEASE_NOTES.md (2309b), scripts/install_hookaido.sh (4881b), SKILL.md (8804b), _meta.json (127b)\n\nFile v2.0.1:SKILL.md\n\n---\r\nname: claw-skill-hookaido\r\ndescription: Receive incoming webhooks from external services and trigger automations, integrations, and event-driven workflows. Operate Hookaido v2 inbound/outbound/internal webhook flows, queue triage, MCP workflows, release verification, and HTTP/gRPC pull workers. Use when tasks involve Hookaidofile authoring, queue backend selection (`sqlite`, `memory`, `postgres`), `hookaido` CLI commands (`run`, `config fmt`, `config validate`, `mcp serve`), pull operations (`dequeue`/`ack`/`nack`/`extend`) over HTTP or gRPC, Admin API backlog/DLQ handling, or production hardening for ingress and delivery.\r\nmetadata: {\"openclaw\":{\"homepage\":\"https://github.com/7schmiede/claw-skill-hookaido\",\"requires\":{\"bins\":[\"hookaido\"]},\"install\":[{\"id\":\"download-darwin-amd64\",\"kind\":\"download\",\"os\":[\"darwin\"],\"url\":\"https://github.com/nuetzliches/hookaido/releases/download/v2.0.0/hookaido_v2.0.0_darwin_amd64.tar.gz\",\"archive\":\"tar.gz\",\"extract\":true,\"stripComponents\":1,\"targetDir\":\"~/.local/bin\",\"bins\":[\"hookaido\"],\"label\":\"Download hookaido v2.0.0 (macOS amd64)\"},{\"id\":\"download-darwin-arm64\",\"kind\":\"download\",\"os\":[\"darwin\"],\"url\":\"https://github.com/nuetzliches/hookaido/releases/download/v2.0.0/hookaido_v2.0.0_darwin_arm64.tar.gz\",\"archive\":\"tar.gz\",\"extract\":true,\"stripComponents\":1,\"targetDir\":\"~/.local/bin\",\"bins\":[\"hookaido\"],\"label\":\"Download hookaido v2.0.0 (macOS arm64)\"},{\"id\":\"download-linux-amd64\",\"kind\":\"download\",\"os\":[\"linux\"],\"url\":\"https://github.com/nuetzliches/hookaido/releases/download/v2.0.0/hookaido_v2.0.0_linux_amd64.tar.gz\",\"archive\":\"tar.gz\",\"extract\":true,\"stripComponents\":1,\"targetDir\":\"~/.local/bin\",\"bins\":[\"hookaido\"],\"label\":\"Download hookaido v2.0.0 (Linux amd64)\"},{\"id\":\"download-linux-arm64\",\"kind\":\"download\",\"os\":[\"linux\"],\"url\":\"https://github.com/nuetzliches/hookaido/releases/download/v2.0.0/hookaido_v2.0.0_linux_arm64.tar.gz\",\"archive\":\"tar.gz\",\"extract\":true,\"stripComponents\":1,\"targetDir\":\"~/.local/bin\",\"bins\":[\"hookaido\"],\"label\":\"Download hookaido v2.0.0 (Linux arm64)\"},{\"id\":\"download-windows-amd64\",\"kind\":\"download\",\"os\":[\"win32\"],\"url\":\"https://github.com/nuetzliches/hookaido/releases/download/v2.0.0/hookaido_v2.0.0_windows_amd64.zip\",\"archive\":\"zip\",\"extract\":true,\"targetDir\":\"~/.openclaw/tools/hookaido\",\"bins\":[\"hookaido\"],\"label\":\"Download hookaido v2.0.0 (Windows amd64)\"},{\"id\":\"download-windows-arm64\",\"kind\":\"download\",\"os\":[\"win32\"],\"url\":\"https://github.com/nuetzliches/hookaido/releases/download/v2.0.0/hookaido_v2.0.0_windows_arm64.zip\",\"archive\":\"zip\",\"extract\":true,\"targetDir\":\"~/.openclaw/tools/hookaido\",\"bins\":[\"hookaido\"],\"label\":\"Download hookaido v2.0.0 (Windows arm64)\"}]}}\r\n---\r\n\r\n# Hookaido\r\n\r\n## Overview\r\n\r\nImplement and troubleshoot Hookaido with a config-first workflow: edit `Hookaidofile`, validate, run, exercise ingress/pull flows, then diagnose queue health and DLQ behavior.\r\nTreat Hookaido v2.0.0's modular architecture as additive in this skill: keep the existing workflow intact by default, and opt into modules such as `postgres`, gRPC workers, or release verification only when they materially help the task.\r\nUse conservative, reversible changes and validate before runtime operations.\r\n\r\n## Workflow\r\n\r\n1. Confirm target topology: inbound+pull (HTTP or gRPC), push outbound, or internal queue, plus the queue backend (`sqlite`, `memory`, or `postgres`).\r\n2. Choose runtime mode and ensure `hookaido` exists where tools execute.\r\n   - Host-binary mode: use the install action from `metadata.openclaw.install`.\r\n   - Host fallback: run `bash {baseDir}/scripts/install_hookaido.sh` (pinned `v2.0.0`, SHA256-verified).\r\n   - Public repo/source mode: use the public upstream repo `github.com/nuetzliches/hookaido` via `go install github.com/nuetzliches/hookaido/cmd/hookaido@v2.0.0` when a source-based install is preferred.\r\n   - Docker-sandbox mode: use a sandbox image that already includes `hookaido` (preferred), or install inside sandbox via `agents.defaults.sandbox.docker.setupCommand`.\r\n   - Keep host install actions available as fallback and to satisfy `metadata.openclaw.requires.bins`.\r\n3. Inspect and update `Hookaidofile` minimally.\r\n4. Run format and validation before starting or reloading:\r\n   - `hookaido config fmt --config ./Hookaidofile`\r\n   - `hookaido config validate --config ./Hookaidofile`\r\n   - `hookaido config validate --config ./Hookaidofile --strict-secrets` when secret refs or Vault-backed config are involved.\r\n5. Start runtime and verify health:\r\n   - `hookaido run --config ./Hookaidofile --db ./.data/hookaido.db`\r\n   - `hookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"` when `queue postgres` is selected.\r\n   - `curl http://127.0.0.1:2019/healthz?details=1`\r\n6. Validate end-to-end behavior:\r\n   - ingress request accepted and queued\r\n   - consumer `dequeue`/`ack`/`nack`/`extend` path works (HTTP pull, batch `ack`/`nack`, plus gRPC pull when enabled)\r\n7. For incidents, inspect backlog and DLQ first, then mutate.\r\n\r\n## Task Playbooks\r\n\r\n### Configure Ingress and Pull Consumption\r\n\r\n1. Define a route with explicit auth and pull path (HTTP pull, optional gRPC pull worker listener).\r\n2. Keep secrets in env/file refs, never inline.\r\n3. Verify route and global pull auth are consistent.\r\n4. Test with a real webhook payload and a dequeue/ack cycle, using batch `ack`/`nack` when worker throughput matters.\r\n\r\nPrefer this baseline:\r\n\r\n```hcl\r\ningress {\r\n  listen :8080\r\n}\r\n\r\npull_api {\r\n  listen :9443\r\n  grpc_listen :9943 # optional gRPC pull-worker listener\r\n  auth token env:HOOKAIDO_PULL_TOKEN\r\n}\r\n\r\n/webhooks/github {\r\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\r\n  pull { path /pull/github }\r\n}\r\n```\r\n\r\n### Configure Push Delivery\r\n\r\n1. Use push delivery only when inbound connectivity to the service is acceptable.\r\n2. Set timeout and retry policy explicitly.\r\n3. Validate downstream idempotency since delivery is at-least-once.\r\n\r\n```hcl\r\n/webhooks/stripe {\r\n  auth hmac env:STRIPE_SIGNING_SECRET\r\n  deliver \"https://billing.internal/stripe\" {\r\n    retry exponential max 8 base 2s cap 2m jitter 0.2\r\n    timeout 10s\r\n  }\r\n}\r\n```\r\n\r\n### Configure Queue Backends\r\n\r\n1. Default to `sqlite` unless the task explicitly needs ephemeral dev mode or shared Postgres storage.\r\n2. Treat `memory` and `postgres` as additive v2 modules, not replacements for existing sqlite workflows.\r\n3. When using `postgres`, document the DSN source and validate health plus backlog endpoints after startup.\r\n\r\nPrefer these patterns:\r\n\r\n```hcl\r\nqueue sqlite\r\n\r\nqueue memory\r\n\r\nqueue postgres\r\n```\r\n\r\n### Operate Queue and DLQ\r\n\r\n1. Start with health details and backlog endpoints.\r\n2. Inspect DLQ before requeue or delete.\r\n3. If requeueing many items, explain expected impact and rollback path.\r\n4. Require clear operator reason strings for mutating admin calls.\r\n\r\nUse:\r\n\r\n- `GET /healthz?details=1`\r\n- `GET /backlog/trends`\r\n- `GET /dlq`\r\n- `POST /dlq/requeue`\r\n- `POST /dlq/delete`\r\n\r\n### Use MCP Mode for AI Operations\r\n\r\n1. Default to `--role read` for diagnostics.\r\n2. Enable mutations only with explicit operator intent:\r\n   - `--enable-mutations --role operate --principal <identity>`\r\n3. Enable runtime control only for admin workflows:\r\n   - `--enable-runtime-control --role admin --pid-file <path>`\r\n4. Include `reason` for mutation calls and keep it specific.\r\n\r\n### Verify Public Releases\r\n\r\n1. Prefer official release assets from the public Hookaido repo.\r\n2. When supply-chain assurance matters, validate checksums, signature material, and provenance before rollout.\r\n3. Keep verification optional by default so existing skill flows do not become heavier unless the task requires it.\r\n\r\nUse:\r\n\r\n- `hookaido verify-release --checksums ./hookaido_v2.0.0_checksums.txt --require-provenance`\r\n\r\n## Validation Checklist\r\n\r\n- `hookaido config validate` returns success before runtime start/reload.\r\n- `hookaido config validate --strict-secrets` is used when secret refs, Vault, or public-release rollout validation matters.\r\n- Health endpoint is reachable and reports expected queue/backend state.\r\n- Pull consumer can `dequeue`, `ack`, `nack`, and `extend` with valid token (HTTP and optional gRPC transport), including batch `ack`/`nack` when enabled.\r\n- For push mode, retry/timeout behavior is explicitly configured.\r\n- For `queue postgres`, runtime is started with `--postgres-dsn` or `HOOKAIDO_POSTGRES_DSN`.\r\n- Any DLQ mutation is scoped, justified, and logged.\r\n\r\n## Safety Rules\r\n\r\n- Do not disable auth to \"make tests pass.\"\r\n- Do not suggest direct mutations before read-only diagnostics.\r\n- Treat queue operations as at-least-once; require idempotent handlers.\r\n- Keep secrets in `env:` or `file:` refs.\r\n\r\n## References\r\n\r\n- Read `references/operations.md` for command snippets and API payload templates.\n\nFile v2.0.1:README.md\n\n# claw-skill-hookaido\r\n\r\nPublic OpenClaw skill repository for Hookaido.\r\n\r\nRepository link for skill distribution:\r\n\r\n- `https://github.com/7schmiede/claw-skill-hookaido`\r\n\r\nUpstream Hookaido project:\r\n\r\n- `https://github.com/nuetzliches/hookaido`\r\n\r\nThis skill is pinned to Hookaido `v2.0.0` and keeps existing inbound/outbound/pull workflows as the default path.\r\nNew v2 capabilities such as `queue postgres`, gRPC pull workers, batch `ack`/`nack`, and release verification are documented as additive modules so existing usage does not receive breaking changes by default.\r\n\r\nMain files:\r\n\r\n- `SKILL.md` for skill metadata and operating guidance\r\n- `references/operations.md` for install, runtime, and API command examples\r\n- `scripts/install_hookaido.sh` for pinned release-binary installation with SHA256 verification\r\n- `RELEASE_NOTES.md` for the current public skill release summary\n\nFile v2.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn70n9zjjpmw2dg19a8n5w8bm1813vkf\",\n  \"slug\": \"hookaido\",\n  \"version\": \"2.0.1\",\n  \"publishedAt\": 1773161619049\n}\n\nFile v2.0.1:references/operations.md\n\n# Hookaido Operations Reference\r\n\r\nUse this file for concrete command syntax and request payloads.\r\n\r\n## Install Hookaido\r\n\r\nOpenClaw supports two runtime variants.\r\n\r\nPublic repositories:\r\n\r\n- Upstream project: `https://github.com/nuetzliches/hookaido`\r\n- Public skill repo: `https://github.com/7schmiede/claw-skill-hookaido`\r\n\r\n### Variant A: Host Binary (Gateway/Host)\r\n\r\n- Use one of the skill installer actions from `metadata.openclaw.install` (platform + architecture specific download).\r\n- Choose the artifact that matches your host architecture (`amd64` or `arm64`).\r\n- The OpenClaw download URLs are pinned to Hookaido `v2.0.0`.\r\n- macOS/Linux installers extract to `~/.local/bin` (with `stripComponents: 1`).\r\n- Windows installers extract to `~/.openclaw/tools/hookaido`.\r\n\r\nDirect CLI fallback:\r\n\r\n```bash\r\ngo install github.com/nuetzliches/hookaido/cmd/hookaido@v2.0.0\r\n```\r\n\r\nRelease-binary fallback from this skill folder:\r\n\r\n```bash\r\nbash {baseDir}/scripts/install_hookaido.sh\r\n```\r\n\r\nThe fallback installer is hardened:\r\n\r\n- Defaults to pinned `v2.0.0` (no dynamic `latest` lookup).\r\n- Verifies SHA256 of the downloaded release artifact before extraction/install.\r\n\r\nOptional pins/overrides for the installer script:\r\n\r\n```bash\r\n# Default pinned install, custom location\r\nHOOKAIDO_INSTALL_DIR=\"$HOME/bin\" bash {baseDir}/scripts/install_hookaido.sh\r\n\r\n# Non-default release requires explicit checksum\r\nHOOKAIDO_VERSION=v2.0.1 \\\r\nHOOKAIDO_SHA256=\"<artifact-sha256>\" \\\r\nbash {baseDir}/scripts/install_hookaido.sh\r\n```\r\n\r\n### Variant B: Docker Sandbox\r\n\r\n- OpenClaw supports Docker sandbox mode via `sandboxing.enabled: true` and `sandboxing.type: docker`.\r\n- Preferred: provide a custom sandbox image with `hookaido` preinstalled, and pin the image by immutable digest.\r\n- Optional: use `agents.defaults.sandbox.docker.setupCommand` to install `hookaido` inside the container at startup.\r\n- Keep `metadata.openclaw.install` as fallback and for `metadata.openclaw.requires.bins` checks on the host.\r\n\r\n## Core CLI Commands\r\n\r\n```bash\r\n# Validate and format config\r\nhookaido config fmt --config ./Hookaidofile\r\nhookaido config validate --config ./Hookaidofile\r\nhookaido config validate --config ./Hookaidofile --strict-secrets\r\n\r\n# Start runtime\r\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db\r\n\r\n# Start runtime with Postgres queue backend\r\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\r\n\r\n# Start runtime with live config watch\r\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db --watch\r\n\r\n# Start MCP server (read-only)\r\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\r\n\r\n# Verify a public release bundle before rollout\r\nhookaido verify-release \\\r\n  --checksums ./hookaido_v2.0.0_checksums.txt \\\r\n  --public-key ./hookaido_v2.0.0_checksums.txt.pub.pem \\\r\n  --require-provenance\r\n```\r\n\r\n## Minimal Pull-Mode Config\r\n\r\n```hcl\r\ningress {\r\n  listen :8080\r\n}\r\n\r\npull_api {\r\n  listen :9443\r\n  auth token env:HOOKAIDO_PULL_TOKEN\r\n}\r\n\r\n/webhooks/github {\r\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\r\n  pull { path /pull/github }\r\n}\r\n```\r\n\r\n## Pull API Calls\r\n\r\nAssume base URL `http://localhost:9443/pull/github` and token in `HOOKAIDO_PULL_TOKEN`.\r\n\r\n```bash\r\n# Dequeue\r\ncurl -sS -X POST \"http://localhost:9443/pull/github/dequeue\" \\\r\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -d '{\"batch\":10,\"lease_ttl\":\"30s\",\"max_wait\":\"5s\"}'\r\n\r\n# Ack\r\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\r\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -d '{\"lease_id\":\"lease_xyz\"}'\r\n\r\n# Batch ack (v2.0.0+)\r\ncurl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\r\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -d '{\"lease_ids\":[\"lease_a\",\"lease_b\"]}'\r\n\r\n# Nack (requeue with delay)\r\ncurl -sS -X POST \"http://localhost:9443/pull/github/nack\" \\\r\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -d '{\"lease_id\":\"lease_xyz\",\"delay\":\"5s\",\"dead\":false}'\r\n\r\n# Extend lease\r\ncurl -sS -X POST \"http://localhost:9443/pull/github/extend\" \\\r\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\r\n  -H \"Content-Type: application/json\" \\\r\n  -d '{\"lease_id\":\"lease_xyz\",\"lease_ttl\":\"30s\"}'\r\n\r\n# Batch\n\nArchive v2.0.0: 7 files, 10269 bytes\n\nFiles: agents/openai.yaml (262b), README.md (868b), references/operations.md (6930b), RELEASE_NOTES.md (2267b), scripts/install_hookaido.sh (4705b), SKILL.md (8555b), _meta.json (127b)\n\nArchive v1.5.0: 5 files, 7393 bytes\n\nFiles: agents/openai.yaml (262b), references/operations.md (5543b), scripts/install_hookaido.sh (4705b), SKILL.md (6504b), _meta.json (127b)\n\nArchive v1.4.0: 5 files, 7373 bytes\n\nFiles: agents/openai.yaml (248b), references/operations.md (5543b), scripts/install_hookaido.sh (4705b), SKILL.md (6487b), _meta.json (127b)\n\nArchive v1.3.0: 5 files, 6975 bytes\n\nFiles: agents/openai.yaml (205b), references/operations.md (4816b), scripts/install_hookaido.sh (4691b), SKILL.md (6212b), _meta.json (127b)","readmeExcerpt":"Skill: Hookaido Webhook Integration Owner: 7schmiede Summary: Webhook infrastructure for receiving, queuing, and delivering webhooks. Operate Hookaido webhook ingress, durable webhook queue (SQLite/Postgres), webhook de... Tags: latest:2.6.0 Version history: v2.6.0 | 2026-04-20T22:20:18.274Z | user - Version bump to 2.6.0 with updated binaries and install sources. - Added a LICENSE file. - Support for new webhook pro","codeSnippets":[],"executableExamples":[{"language":"hcl","snippet":"ingress {\n  listen :8080\n}\n\npull_api {\n  listen :9443\n  grpc_listen :9943 # optional gRPC pull-worker listener\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\n  pull { path /pull/github }\n}"},{"language":"hcl","snippet":"/webhooks/stripe {\n  auth hmac env:STRIPE_SIGNING_SECRET\n  deliver \"https://billing.internal/stripe\" {\n    retry exponential max 8 base 2s cap 2m jitter 0.2\n    timeout 10s\n  }\n}"},{"language":"hcl","snippet":"/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  deliver exec \"/opt/hooks/deploy.sh\" {\n    timeout 30s\n    retry exponential max 3 base 1s cap 30s jitter 0.2\n    env DEPLOY_ENV production\n    env NOTIFY_URL {env.SLACK_WEBHOOK_URL}\n  }\n}"},{"language":"hcl","snippet":"/webhooks/github {\n  auth hmac {\n    provider github\n    secret env:GITHUB_WEBHOOK_SECRET\n  }\n  pull { path /pull/github }\n}\n\n/webhooks/gitea {\n  auth hmac {\n    provider gitea\n    secret env:GITEA_WEBHOOK_SECRET\n  }\n  pull { path /pull/gitea }\n}\n\n/webhooks/stripe {\n  auth hmac {\n    provider stripe\n    secret env:STRIPE_SIGNING_SECRET\n  }\n  pull { path /pull/stripe }\n}\n\n/webhooks/cituro {\n  auth hmac {\n    provider cituro\n    secret env:CITURO_WEBHOOK_SECRET\n  }\n  pull { path /pull/cituro }\n}"},{"language":"bash","snippet":"curl -sS -N \"http://localhost:9443/pull/github/stream\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\""},{"language":"bash","snippet":"curl -sS -X POST \"http://localhost:9443/pull/github/ack\" \\\n  -H \"Authorization: Bearer $HOOKAIDO_PULL_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"lease_id\":\"lease_xyz\"}'"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: hookaido\nversion: \"2.6.0\"\ndescription: >-\n  Webhook infrastructure for receiving, queuing, and delivering webhooks.\n  Operate Hookaido webhook ingress, durable webhook queue (SQLite/Postgres),\n  webhook delivery (HTTP push, subprocess exec, pull API, SSE streaming),\n  webhook signature verification (HMAC, GitHub, Gitea, Stripe, Cituro),\n  dead-letter queue, and webhook retry policies. Use when tasks involve webhook\n  endpoint configuration (Hookaidofile), webhook queue backends (sqlite, memory,\n  postgres), hookaido CLI (run, config fmt, config validate, mcp serve),\n  webhook consumption (dequeue/ack/nack/extend) over HTTP, SSE, or gRPC,\n  subprocess webhook handlers (deliver exec), webhook provider HMAC\n  (GitHub/Gitea/Stripe/Cituro), Admin API webhook backlog/DLQ triage, or\n  production webhook hardening.\nmetadata:\n  openclaw:\n    homepage: https://github.com/7schmiede/claw-skill-hookaido\n    emoji: \"\\U0001FA9D\"\n    primaryEnv: HOOKAIDO_PULL_TOKEN\n    requires:\n      bins:\n        - hookaido\n      env:\n        - HOOKAIDO_PULL_TOKEN\n        - HOOKAIDO_INGRESS_SECRET\n    install:\n      - id: go-install\n        kind: go\n        package: github.com/nuetzliches/hookaido/cmd/hookaido@v2.6.0\n        bins:\n          - hookaido\n      - id: download-darwin-amd64\n        kind: download\n        os:\n          - darwin\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.6.0/hookaido_v2.6.0_darwin_amd64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.6.0 (macOS amd64)\n      - id: download-darwin-arm64\n        kind: download\n        os:\n          - darwin\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.6.0/hookaido_v2.6.0_darwin_arm64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.6.0 (macOS arm64)\n      - id: download-linux-amd64\n        kind: download\n        os:\n          - linux\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.6.0/hookaido_v2.6.0_linux_amd64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.6.0 (Linux amd64)\n      - id: download-linux-arm64\n        kind: download\n        os:\n          - linux\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.6.0/hookaido_v2.6.0_linux_arm64.tar.gz\n        archive: tar.gz\n        extract: true\n        stripComponents: 1\n        targetDir: ~/.local/bin\n        bins:\n          - hookaido\n        label: Download hookaido v2.6.0 (Linux arm64)\n      - id: download-windows-amd64\n        kind: download\n        os:\n          - win32\n        url: https://github.com/nuetzliches/hookaido/releases/download/v2.6.0/hooka"},{"path":"README.md","content":"# hookaido\n\nPublic OpenClaw skill for [Hookaido](https://github.com/nuetzliches/hookaido) — webhook infrastructure that just works.\n\nRepository link for skill distribution:\n\n- `https://github.com/7schmiede/claw-skill-hookaido`\n\nUpstream Hookaido project:\n\n- `https://github.com/nuetzliches/hookaido`\n\nThis skill is pinned to Hookaido `v2.6.0` and keeps existing inbound/outbound/pull workflows as the default path.\nNew capabilities such as `deliver exec` (subprocess delivery), provider-compatible HMAC (GitHub/Gitea/Stripe/Cituro), SSE streaming (`{pull.path}/stream`), `queue postgres`, gRPC pull workers, batch `ack`/`nack`, and release verification are documented as additive modules so existing usage does not receive breaking changes by default.\n\nMain files:\n\n- `SKILL.md` for skill metadata and operating guidance\n- `references/operations.md` for install, runtime, and API command examples\n- `scripts/install_hookaido.sh` for pinned release-binary installation with SHA256 verification\n- `RELEASE_NOTES.md` for the current public skill release summary"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn70n9zjjpmw2dg19a8n5w8bm1813vkf\",\n  \"slug\": \"hookaido\",\n  \"version\": \"2.6.0\",\n  \"publishedAt\": 1776723618274\n}"},{"path":"references/operations.md","content":"# Hookaido Operations Reference\n\nUse this file for concrete command syntax and request payloads.\n\n## Install Hookaido\n\nOpenClaw supports two runtime variants.\n\nPublic repositories:\n\n- Upstream project: `https://github.com/nuetzliches/hookaido`\n- Public skill repo: `https://github.com/7schmiede/claw-skill-hookaido`\n\n### Variant A: Host Binary (Gateway/Host)\n\n- Use one of the skill installer actions from `metadata.openclaw.install` (platform + architecture specific download).\n- Choose the artifact that matches your host architecture (`amd64` or `arm64`).\n- The OpenClaw download URLs are pinned to Hookaido `v2.6.0`.\n- macOS/Linux installers extract to `~/.local/bin` (with `stripComponents: 1`).\n- Windows installers extract to `~/.openclaw/tools/hookaido`.\n\nDirect CLI fallback:\n\n```bash\ngo install github.com/nuetzliches/hookaido/cmd/hookaido@v2.6.0\n```\n\nRelease-binary fallback from this skill folder:\n\n```bash\nbash {baseDir}/scripts/install_hookaido.sh\n```\n\nThe fallback installer is hardened:\n\n- Defaults to pinned `v2.6.0` (no dynamic `latest` lookup).\n- Verifies SHA256 of the downloaded release artifact before extraction/install.\n\nOptional pins/overrides for the installer script:\n\n```bash\n# Default pinned install, custom location\nHOOKAIDO_INSTALL_DIR=\"$HOME/bin\" bash {baseDir}/scripts/install_hookaido.sh\n\n# Non-default release requires explicit checksum\nHOOKAIDO_VERSION=v2.0.1 \\\nHOOKAIDO_SHA256=\"<artifact-sha256>\" \\\nbash {baseDir}/scripts/install_hookaido.sh\n```\n\n### Variant B: Docker Sandbox\n\n- OpenClaw supports Docker sandbox mode via `sandboxing.enabled: true` and `sandboxing.type: docker`.\n- Preferred: provide a custom sandbox image with `hookaido` preinstalled, and pin the image by immutable digest.\n- Optional: use `agents.defaults.sandbox.docker.setupCommand` to install `hookaido` inside the container at startup.\n- Keep `metadata.openclaw.install` as fallback and for `metadata.openclaw.requires.bins` checks on the host.\n\n## Core CLI Commands\n\n```bash\n# Validate and format config\nhookaido config fmt --config ./Hookaidofile\nhookaido config validate --config ./Hookaidofile\nhookaido config validate --config ./Hookaidofile --strict-secrets\n\n# Start runtime\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db\n\n# Start runtime with Postgres queue backend\nhookaido run --config ./Hookaidofile --postgres-dsn \"$HOOKAIDO_POSTGRES_DSN\"\n\n# Start runtime with live config watch\nhookaido run --config ./Hookaidofile --db ./.data/hookaido.db --watch\n\n# Start MCP server (read-only)\nhookaido mcp serve --config ./Hookaidofile --db ./.data/hookaido.db --role read\n\n# Verify a public release bundle before rollout\nhookaido verify-release \\\n  --checksums ./hookaido_v2.6.0_checksums.txt \\\n  --public-key ./hookaido_v2.6.0_checksums.txt.pub.pem \\\n  --require-provenance\n```\n\n## Minimal Pull-Mode Config\n\n```hcl\ningress {\n  listen :8080\n}\n\npull_api {\n  listen :9443\n  auth token env:HOOKAIDO_PULL_TOKEN\n}\n\n/webhooks/github {\n  auth hmac env:HOOKAIDO_INGRESS_SECRET\n  pul"},{"path":"RELEASE_NOTES.md","content":"# Release Notes\n\n## GitHub Release Summary\n\nRecommended tag: `v2.6.0`\n\nFeature update pinning to upstream Hookaido `v2.6.0`.\nNew: Stripe and Cituro HMAC providers, SSE streaming endpoint, Claude Code MCP plugin guidance.\n\n## v2.6.0 - 2026-04-21\n\nFeature update pinning to upstream Hookaido `v2.6.0`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.6.0`.\n- Added `provider stripe` and `provider cituro` to provider-compatible HMAC config (v2.6.0 upstream).\n- Added SSE streaming playbook: `GET {pull.path}/stream` for real-time webhook delivery without polling (v2.5.3 upstream).\n- Added Claude Code MCP plugin configuration examples (`.claude/settings.json`) for read and operate roles.\n\n### Compatibility\n\nAdditive coverage. All existing skill workflows remain unchanged.\n\n## v2.2.2 - 2026-04-15\n\nPerformance update pinning to upstream Hookaido `v2.2.2`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.2`.\n- Upstream fix: queue dequeue loop now uses event-driven channel notification instead of 25ms polling. Enqueue signals waiting Dequeue goroutines immediately; fallback polling raised to 1s for delayed/retry items only. Idle CPU drops from ~26% to <1% (SQLite and PostgreSQL backends).\n\n### Compatibility\n\nNo new features. All existing skill workflows remain unchanged.\n\n## v2.2.1 - 2026-03-30\n\nBugfix-only update pinning to upstream Hookaido `v2.2.1`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.1`.\n- Upstream fixes: dispatcher delivery logging (previously silent), zero-target route warning, hot-reload for delivery config changes via `--watch`/SIGHUP.\n\n### Compatibility\n\nNo new features. All existing skill workflows remain unchanged.\n\n## v2.2.0 - 2026-03-28\n\nThis release updates the public Hookaido skill to upstream Hookaido `v2.2.0`.\n\n### Highlights\n\n- Pinned all binary installer actions and checksums to Hookaido `v2.2.0`.\n- Added `deliver exec` playbook for subprocess delivery (payload on stdin, exit-code retry semantics).\n- Added provider-compatible HMAC playbook for GitHub (`X-Hub-Signature-256`) and Gitea/Forgejo (`X-Gitea-Signature`).\n- Updated operations reference with exec delivery and provider-HMAC config examples.\n\n### Compatibility\n\nAdditive v2.2.0 coverage includes:\n\n- `deliver exec` for local script/binary execution with env-var metadata and exit-code retry semantics\n- `auth hmac { provider github }` / `auth hmac { provider gitea }` for native webhook signature verification\n- Custom outbound headers in deliver blocks with placeholder interpolation\n\nAll existing skill workflows remain unchanged.\n\n## v2.0.0 - 2026-03-09\n\nThis release updates the public Hookaido skill to upstream Hookaido `v2.0.0` and prepares the repository for distribution via its public GitHub URL.\n\n### Highlights\n\n- Pinned all binary installer actions to Hookaido `v2.0.0`.\n- Updated the fallback installer script with the official `v2.0.0` SHA256 checksums for macO"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1812,"uniquenessScore":37,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T20:12:46.942Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T20:12:46.942Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T02:15:59.948Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}