# SnapHook > A throwaway webhook endpoint, one click away. Generate a URL, point a sender at > it, and read the request exactly as it arrived — method, path, headers, query > string and body. No account, no install, and nothing you send is kept. Live at https://snaphook.site. Everything here is also written out on the pages linked at the bottom; this is the short version, for anyone reading the site through a tool rather than a browser. ## Getting an endpoint Press the button on the homepage. You get a session with two URLs: - https://snaphook.site/w/{slug} — the endpoint. Give it to whatever you are debugging. Every method is accepted, and anything you append to the path, such as /w/{slug}/orders/created, is captured too. - https://snaphook.site/app/{slug} — the inspector. Open it in a browser and captures appear the instant they land, newest first, with nothing to refresh. There is no account to create, no key to configure and no SDK to install. ## The session URL is the credential The slug is 12 random characters, and since there are no accounts it is the only thing protecting the session. Nobody can guess it, but anyone you hand it to can read every capture in it. Share it the way you would share a password, and keep it out of issues, gists and screenshots. Send test-mode credentials only — no live API keys, bearer tokens, session cookies or signing secrets — and no real customer data. Nothing is written down anywhere and the session is purged on its own, but an inspection endpoint is still the wrong place for anything you would mind a stranger reading. ## What a session will hold - Body size: 256 KB. A larger request still succeeds; you get the first 256 KB, marked as truncated. - Captures: 30 per session. The oldest drops off as a new one arrives. - Lifetime: 2 hours after the last request it received and the last inspector tab closing. After that the URL returns 404. - Sending rate: fair use. Bursts are fine. Flood it and you get a 429 that tells you how long to wait. None of these are upsell gates — there is no paid tier. They are there so one busy endpoint cannot spoil the service for everybody else. ## Pages - [Home](https://snaphook.site/): what the service does, and the button that starts a session. - [Docs](https://snaphook.site/docs): quickstart, URL anatomy, copyable examples for curl, JavaScript and Python, a tour of the inspector, the limits above, wiring up real senders such as Stripe and GitHub, security notes, and an FAQ. - [Privacy](https://snaphook.site/privacy): what is held and for how long, and what is never collected — no accounts, no cookies, no analytics. - [Terms](https://snaphook.site/terms): what the endpoint may and may not be used for. - [Contact](https://snaphook.site/contact): how to report a bug, ask a question or raise a security issue. ## If you are crawling The five pages above are the whole public site, and they are listed in https://snaphook.site/sitemap.xml. Everything under /w/ and /app/ belongs to somebody's session: those paths are disallowed in robots.txt and served with noindex, and they should not be crawled, indexed or quoted.