Webhook Endpoint Management
Let users choose where the app sends events, and which events go there.
What it adds
Creating, editing, and testing outbound webhook endpoints, with destination validation and per-endpoint event subscriptions.
What your agent is told to do
6
What your agent is told to do
6-
1
Let users register endpoints with a URL and a chosen set of event types. Default the subscription to nothing — an endpoint that silently receives every event is a data leak waiting to happen.
-
2
Require HTTPS and validate the destination before saving: resolve the host and refuse private, loopback, link-local, and metadata-service addresses.
-
3
Re-resolve and re-check the destination at delivery time, not only at save time. DNS can be repointed at an internal address after validation passes.
-
4
Offer a test delivery that sends a clearly-marked sample event and shows the raw response. Keep test deliveries out of production event history and out of any delivery-success metrics.
-
5
Signing secrets, retries and backoff, per-attempt delivery logs, replay, and auto-disabling repeatedly-failing endpoints are all owned by Webhook Delivery Log and Retry. Extend that feature rather than building a second delivery system here.
-
6
Show the current state of each endpoint — enabled, disabled by the user, or disabled by the system — and link through to its delivery history.
Edge cases it handles
6
Edge cases it handles
6- A redirect can move a validated public URL to a private one. Do not follow redirects on delivery.
- A URL that resolves to different addresses on each lookup will pass validation once and fail safety later. Check every resolved address, not just the first.
- Changing an endpoint's subscribed events must not retroactively change what already-queued deliveries contain.
- Deleting an endpoint with deliveries in flight must stop future attempts without erasing the history someone may be debugging.
- Two endpoints pointing at the same URL are legitimate — different event sets, different environments. Warn, do not block.
- Endpoint management is a privileged action. Someone who can add a destination can exfiltrate every event in the workspace, so gate it by role and audit every change.
Definition of done
8
Definition of done
8- Endpoints require HTTPS and are rejected when the destination resolves to a private or link-local address.
- Destination safety is re-checked at delivery time and redirects are not followed.
- Each endpoint subscribes to an explicit list of event types, empty by default.
- Test deliveries are visibly marked and excluded from production delivery history.
- The endpoint's enabled or disabled state, and who or what disabled it, is visible.
- Creating, editing, and deleting endpoints is role-gated and audited.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
AI Cost Budgets
AI Cost Budgets
Cap what AI features are allowed to spend before the bill arrives.
What it does
Monetary spending limits on AI work, scoped by workspace, feature, and time period, enforced before a run starts.
How it works
- 1 Find every place the app calls a model and route all of them through one accounting point that records estimated and actual spend against a scope. A budget that only covers the chat feature is not a budget.
- 2 Estimate the cost of a run from the size of its input before dispatching it, and refuse anything that would exceed the remaining budget on its own.
- 3 Reserve the estimate against the budget when the run starts, then reconcile to the real usage figures when it finishes, releasing whatever was over-reserved.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/ai-cost-budgets
Prompt Versioning
Prompt Versioning
Tie every AI output to the exact prompt version that produced it.
What it does
Immutable, numbered versions of each prompt, with the run configuration recorded and every output stamped with the version used.
How it works
- 1 Make every publish create a new immutable version rather than overwriting the previous text. Editing history in place destroys the only record of what produced last month's outputs.
- 2 Capture the whole run configuration with each version, not just the wording: which model tier and parameters were used, which tools were available, and the expected output shape. A prompt that behaves differently under different settings is not one prompt.
- 3 Stamp every generated output with the version identifier that produced it, and keep that stamp with the record so an output found later can be traced back to its exact instructions.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/prompt-versioning
Retrieval Debugger
Retrieval Debugger
Show exactly which sources, chunks, and scores produced a given AI answer.
What it does
A per-answer inspector showing the query as issued, the filters applied, the candidate chunks with their scores, and what reached the model.
How it works
- 1 Capture for each answer the query as it was issued, the filters applied, the candidates returned with their scores, and which of those actually made it into the request after the context ceiling was applied.
- 2 Show results after permission filtering, with a count of how many candidates were excluded and why. Displaying the pre-filter set turns the debugger into a way to read content the viewer cannot open.
- 3 Present each scoring stage separately — keyword, semantic, and any reranking — because a chunk that ends up first overall may have been rescued by one stage after being buried by another, and a single blended number hides that.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/retrieval-debugger
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.