GitHub Hookshot
Webhook Directory evidence: Verified

GitHub Hookshot

GitHub Hookshot is a webhook callback from GitHub used for webhook delivery, payment notifications, service callbacks; it appears in server logs as `github-hookshot`.

GitHub-Hookshot/
Operator GitHub
Risk Safe

Overview

GitHub Hookshot is a webhook callback from GitHub used for webhook delivery, payment notifications, service callbacks, and server-to-server integration events.

Its primary user-agent pattern is github-hookshot; related patterns include GitHub Hookshot.

GitHub Hookshot is Verified from current authoritative identity documentation reviewed on 2026-08-07. The identity type is Official Documented.

Robots.txt behavior is not currently confirmed.

GitHub Hookshot can usually be allowed after confirming the source and monitoring request volume.

Identity

User-Agent Pattern
GitHub-Hookshot/
Aliases
GitHub Hookshot
HTTP Agent Examples
github-hookshot
Robots Token
GitHub-Hookshot/
Identity Type
Officially documented
Evidence Method
Match `GitHub-Hookshot/` to the current operator documentation and corroborate the request with operator-controlled verification signals where available; User-Agent strings alone can be spoofed.

Classification

Type
Webhook
Kind
Webhook
Family
GitHub
Purpose
Webhook

Behavior and handling

Common Use
GitHub Hookshot is used for webhook delivery, payment notifications, service callbacks, and server-to-server integration events.
Detection Notes
GitHub Hookshot traffic is primarily detected by the `github-hookshot` user-agent pattern; related patterns include `GitHub Hookshot`. Compare source IPs, reverse DNS, request paths, and crawl cadence with GitHub infrastructure before trusting the traffic.
Respects robots.txt
Unknown
Spoofing Risk
GitHub Hookshot has medium spoofing risk because user-agent strings can be copied; pair the match with DNS, IP, behavior, or operator evidence.
Risk
Safe
Recommended Handling
Depends

Rules and controls

Robots.txt Snippet
# robots.txt behavior is unconfirmed. Do not rely on this rule without verification.

Relationships

Operator
GitHub Checked 2026-08-07

Relationships without an Evidence link are normalized from the canonical directory record. They should not be interpreted as independent proof of physical presence or request origin.

Similar Bots

Webhook Unverified

Zapier

Zapier Inc.

Zapier
Webhook Unverified

Trustly

Trustly Group AB

Trustly