Dashboard
Manage your webhooks at bankr.bot/webhooks.
Overview
The dashboard shows:
- Webhook list — every webhook with status, mode, version, and recent invocation count
- Slide-out detail panel — stats, settings, env vars, and live invocation logs per webhook
- Encrypted env vars — add and remove shared secrets for your handlers
Webhook Detail Panel
Click any webhook to open the slide-out panel. It has four tabs:
Overview
- Status, mode, version, total invocations, last invoked timestamp
- 30-day stats — invocations, success rate, p50 and p95 handler duration
- Your webhook URL — copy-paste ready
- Deploy hint — the CLI command to redeploy this webhook
Logs
Live feed of recent invocations (polls every 10 seconds):
202 POST 2s ago 145ms V1StGXR8 (prompt returned, agent job queued)
401 POST 1m ago 12ms (your verifier rejected it)
502 POST 5m ago 10003ms (handler timed out)
Each row shows the agent job ID when the handler returned a prompt. Click any row to expand:
- Payload preview — the first 500 characters of the body received
- Error — why the invocation failed outside your handler's own response (timeout, crash, rate limit)
Logs are retained for 30 days.
Do not log sensitive information (signing secrets, API keys, user PII) via console.log. Console output is stored with each invocation log.
Settings
All per-webhook permissions can be updated here without redeploying:
- Description — text shown in lists and headers
- Read-only — toggle write access. Flipping to writes requires non-empty
allowedRecipients. - Allowed recipients (EVM) — comma-separated EVM addresses the agent may send to
- Allowed recipients (Solana) — comma-separated Solana addresses
- Rate limit (per minute, per day) — numeric caps (only the per-minute cap is enforced today)
- Max payload bytes — request size cap
Click Save and update — changes take effect within seconds. No redeploy needed.
Delete — at the bottom, a dangerous-action button permanently removes the webhook. Cannot be undone.
Env vars
Shared encrypted env vars for all your webhook handlers. Injected as process.env.KEY.
- Add — enter a KEY (auto-uppercased) and VALUE. Submitted over HTTPS and written to encrypted storage immediately.
- Remove — click "Remove" next to any variable. Takes effect on the next invocation.
Only key names are shown — values are never displayed or transmitted back to the browser. See Security for the full env var isolation model.
Settings at a Glance
The quickest way to understand what a webhook can do:
| Indicator | Meaning |
|---|---|
Green active status | Webhook is serving requests. |
Yellow paused status | Returns 404 to callers until resumed. |
read-only badge | Agent cannot execute write tools for this webhook. |
writes badge | Agent can write — but only to allowedRecipients. |
Flipping read-only off on a webhook with no allowedRecipients is blocked in the UI.