# ShellOrbit > ShellOrbit receives your inbound webhooks, stores every payload, and retries delivery with backoff until your destination answers. ShellOrbit is a hosted webhook receiver and relay for developers running small production applications. It accepts inbound webhooks at an HTTPS ingest endpoint, stores the raw request before attempting anything else, delivers it to destinations you configure, retries with backoff when a destination fails, and lets you replay any stored event. ## Key facts - Category: webhook infrastructure, developer tool. - Ingest URL shape: https://hooks.shellorbit.com/e/{endpoint_id} - Free plan: 15,000 events per month, no card required. - Paid plans start at $15 per month. Full ladder: Hobby $0 for 15,000 events, Starter $15 for 75,000 events, Pro $40 for 150,000 events, Business $99 for 750,000 events. - Retention and replay window by plan: Hobby 3 day retention and replay, Starter 14 day retention and replay, Pro 30 day retention and replay, Business 90 day retention and replay. - Delivery guarantee: at least once. Handlers must tolerate duplicates and out of order arrival. - Events are never deleted for exceeding a plan limit. Paid plans bill overage by the thousand; the free plan queues for 48 hours and warns. - Infrastructure: Amazon Web Services. Authentication: WorkOS. Transactional email: Zoho ZeptoMail. Payments: Paddle as merchant of record. - Uptime commitment: 99.9 percent on Business plans. ## How it works 1. Point the provider at your ingest URL. Create an endpoint and paste the URL into Stripe, GitHub, Shopify, or anything else that sends webhooks. Nothing to install and no library to add. 2. Every request is stored before anything else happens. Method, headers, query, raw body, and signature are written down first. If your server is down, restarting, or mid deploy, the event is already safe. 3. Delivery runs on a queue with backoff. We POST to your destination, record the status code and response time, and requeue with increasing delay when the attempt fails. Permanent failures move to a dead letter queue you can inspect. 4. Replay anything inside your retention window. Fix the bug, then replay a single event, a filtered range, or everything that failed in the last hour. The original payload and headers are sent again, byte for byte. ## Documentation - [Quickstart](https://shellorbit.com/docs/quickstart/): Create an endpoint, point a provider at it, and watch the first delivery land. - [Ingest endpoints](https://shellorbit.com/docs/endpoints/): What an endpoint is, what it accepts, and how to organise endpoints across providers and environments. - [Delivery and retries](https://shellorbit.com/docs/delivery/): How delivery attempts are made, when they are retried, how backoff is calculated, and what your handler must guarantee. - [Replay and the dead letter queue](https://shellorbit.com/docs/replay/): Resend a single event, a filtered range, or everything that failed, using the original bytes. - [Signature verification](https://shellorbit.com/docs/signatures/): Verify the provider's signature on the way in, and verify ours on the way out. - [Payload transformation](https://shellorbit.com/docs/transformations/): Reshape, trim, or enrich the body before it reaches your handler. - [Custom ingest domain](https://shellorbit.com/docs/custom-domains/): Receive on your own hostname instead of a shared ShellOrbit URL. - [Limits, quotas, and overage](https://shellorbit.com/docs/limits/): What each plan includes, what happens when you pass it, and the technical limits that apply to every plan. - [Team, seats, and the audit log](https://shellorbit.com/docs/team/): Who can do what in an organization, how seats are counted and charged, and what the audit log records. - [HTTP API](https://shellorbit.com/docs/api/): Manage endpoints, read events, and trigger replays from your own code. - [Status codes and troubleshooting](https://shellorbit.com/docs/errors/): What each failure means, which side it comes from, and the first thing to check. ## Pages - [Home](https://shellorbit.com/): product overview, pricing, and frequently asked questions. - [Documentation](https://shellorbit.com/docs/): technical reference for ingest, delivery, replay, signatures, limits, and the HTTP API. - [Contact](https://shellorbit.com/contact/): support, general, security, and privacy addresses. - [Terms of Service](https://shellorbit.com/legal/terms/) - [Privacy Policy](https://shellorbit.com/legal/privacy/) - [Data Processing Addendum](https://shellorbit.com/legal/dpa/) - [Refund Policy](https://shellorbit.com/legal/refunds/) - [Subprocessors](https://shellorbit.com/legal/subprocessors/) - [Responsible Disclosure](https://shellorbit.com/legal/responsible-disclosure/) - [Hall of Fame](https://shellorbit.com/legal/hall-of-fame/) ## Answers to common questions Q: What happens when I pass my monthly event limit? A: Nothing gets thrown away. On paid plans you keep receiving and the extra events are billed by usage, at the per thousand rate on your plan. On the free plan we keep accepting and queueing for 48 hours and send you a warning. Delivery resumes as soon as you upgrade. If the plan is still at its limit after that window, delivery slows rather than stopping outright. Q: Do you ever drop an event? A: Not on purpose, and not because of billing. A dropped webhook can be your customer's missed payment, so the design writes the event down before doing anything else. Events leave storage only when they age out of your plan's retention window, or when you delete them. Q: How fast is delivery? A: A healthy first attempt typically leaves within a second of receipt. Retries follow your backoff setting, so a failing destination sees increasing gaps rather than a tight loop. Q: Where does my payload data live? A: On Amazon Web Services. Event records sit in DynamoDB, oversized payloads in S3, and delivery runs through SQS and Lambda. Nothing is copied to a third party for analytics. Q: Can I inspect what the provider actually sent? A: Yes. Raw headers, raw body, signature, and every delivery attempt with its response code and body are visible for the whole retention window. Q: Can I move off ShellOrbit later? A: Point the provider back at your own URL and delivery stops being ours. Export your stored events over the API before you cancel if you want to keep them. Q: How do I cancel? A: From the dashboard, at any time. The plan runs to the end of the paid period and then stops. Payments already made are not refunded, which is set out in the refund policy. Q: Is there an uptime commitment? A: The Business plan carries a 99.9 percent monthly commitment on the ingest endpoint. Lower plans run on the same infrastructure without a contractual target. ## Reporting a security problem - Policy: https://shellorbit.com/legal/responsible-disclosure/ - Machine readable: https://shellorbit.com/.well-known/security.txt - Address: security@shellorbit.com - Credit: valid reports are named at https://shellorbit.com/legal/hall-of-fame/ unless the reporter prefers anonymity. There is no paid bounty. - In scope: shellorbit.com and its subdomains, the dashboard and REST API at https://app.shellorbit.com, and the ingest endpoint at https://hooks.shellorbit.com. - Out of scope: third parties we use but do not operate, namely Paddle, WorkOS, Zoho, Sentry, and Amazon Web Services. Delivering a webhook to a destination the customer configured is the product working, not server side request forgery. ## Contact - Support: support@shellorbit.com - General: contact@shellorbit.com - Security: security@shellorbit.com - Privacy: privacy@shellorbit.com ## Full text A single file containing every page in full is at https://shellorbit.com/llms-full.txt