alchemy-webhooks-events
Operate Alchemy Notify webhooks with raw-body HMAC verification, idempotent intake, durable processing, and safe lifecycle changes
Install / Use
npx skills add jeremylongshore/tons-of-skills-marketplace --skill alchemy-webhooks-eventsInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of alchemy-webhooks-events
alchemy-webhooks-events scores 83/100 on our quality scale, 2765th of 4,659 Development & Engineering skills we index.
Its SKILL.md is 4.9 KB long, well organised into 13 sections and no code examples: a solid amount of guidance for an agent.
With 2,785 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 8 days ago, so alchemy-webhooks-events is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
alchemy-webhooks-events compared with similar skills
All 4 of these similar skills score higher than alchemy-webhooks-events; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| alchemy-webhooks-events (this skill)by jeremylongshore | 83 | 2.8k | 8d ago | SKILL.md |
| ai-job-searchby MadsLorentzen | 100 | 44.8k | today | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 2d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 10d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 10d ago | SKILL.md |
Frequently asked questions
- How do I install alchemy-webhooks-events?
- Run
npx skills add jeremylongshore/tons-of-skills-marketplace --skill alchemy-webhooks-events. The install tabs above show the steps for each supported agent. - Which AI agents does alchemy-webhooks-events work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is alchemy-webhooks-events safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is alchemy-webhooks-events still maintained?
- The repository was last updated 8 days ago, so alchemy-webhooks-events is actively maintained.
Skill content
View source on GitHubname: alchemy-webhooks-events description: >- Operate Alchemy Notify webhooks with raw-body HMAC verification, idempotent intake, durable processing, and safe lifecycle changes. Use when implementing or repairing blockchain event delivery. Trigger with "Alchemy webhook", "Alchemy Notify", or "verify X-Alchemy-Signature". allowed-tools: Read,Glob,Grep,Write,Edit argument-hint: "<webhook-type> <network> <callback>" version: 2.0.0 license: MIT author: Jeremy Longshore jeremy@intentsolutions.io tags: [saas, alchemy, webhooks, events] model: inherit effort: high compatibility: "Designed for Claude Code; live Alchemy access requires network access, an appropriate credential, account capacity, and explicit approval"
Alchemy Notify Webhook Operations
Overview
Operate Alchemy Notify webhooks with raw-body HMAC verification, idempotent intake, durable processing, and safe lifecycle changes. This workflow produces a reviewable artifact and negative-path evidence before any live side effect.
Prerequisites
- Current first-party Alchemy documentation for the selected product, chain, feature, client, authentication method, limit, and lifecycle.
- Named product, application, security, data/privacy, budget, release, and operations owners appropriate to the requested scope.
- Synthetic or approved non-production fixtures, a credential canary, explicit success criteria, and a tested rollback boundary.
Current Contract
Alchemy signs the exact raw request body with HMAC-SHA256 using the webhook's signing key and sends the digest in X-Alchemy-Signature. Notify management uses its documented auth token, not the signing key. Current docs describe automatic retries/backoff and ordered first-time delivery; consumers still need idempotency because duplicate processing and application retries remain possible.
Authentication
Keep the per-webhook signing key and Notify management token in separate managed secrets. The receiver may read the signing key only for verification; it may not create, update, or delete webhook registrations.
Instructions
- Select the current webhook type and network from first-party support, define event semantics, confirmation policy, callback SLO, and data retention.
- Create or modify the registration only through an approved management path; record webhook ID, redacted filter, owner, signing-key version, and rollback configuration.
- Capture the raw request bytes before JSON parsing, compute HMAC-SHA256, and compare decoded equal-length values with a timing-safe function.
- Persist the webhook and event identifiers atomically before acknowledging; enqueue work and return success without blocking on downstream side effects.
- Make consumers idempotent, preserve per-entity ordering where required, and define reorganization, mined, dropped, and duplicate-event behavior.
- Test valid, invalid, replayed, delayed, out-of-order, and downstream-failure cases; operate a bounded dead-letter replay with explicit approval.
Tool Discipline
Use Read, Glob, and Grep to inspect current documentation, configuration, code, fixtures, and evidence. Use Write and Edit only for approved repository artifacts. Skill invocation alone does not authorize network access, credentials, wallet addresses, customer data, plan changes, spend, key creation or rotation, webhook changes, deployment, replay, transaction construction, signing, broadcast, or deletion.
Approval Boundaries
The product owner approves event scope and user impact. Security approves callback exposure and secret storage. Creating, changing, deleting, replaying, or rotating a production webhook requires explicit owner approval.
Error Handling
- Reject a missing, malformed, or mismatched signature before parsing or side effects.
- Do not use the Notify management token as the HMAC signing key.
- A duplicate-safe acknowledgement is preferable to repeating a user-visible side effect.
Output
Return the event contract, registration receipt, raw-body verifier, idempotency key and storage design, acknowledgement SLO, ordering/reorg policy, replay runbook, tests, and rollback. Mark assumptions, observations, source dates, environment-specific behavior, owners, and unresolved gaps explicitly.
Examples
- Accept one synthetic signed Address Activity event, then acknowledge its exact duplicate without repeating a notification.
- Quarantine a valid event when downstream processing fails and replay it only after the fault and approval boundary are resolved.
Validation
Exercise and record expected and observed results for:
- valid signature
- wrong signing key
- body changed after signing
- duplicate event
- out-of-order event
- downstream failure and replay
Resources
- Current first-party evidence map — recheck dated Alchemy sources before execution.
- Treat observed account, application, network, indexer, chain, or provider behavior as environment-specific evidence, never a universal guarantee.
Related Skills
ai-job-search
44.8kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
