webhook / rules
webhook-co/webhook/.cursor/rules/constitution.mdc
Non-negotiable product principles every change must respect.
Cursor rule0 starsChanged 2 months ago
What's in it
- Constitution — non-negotiables
- Engineering guardrails (non-negotiable)
--- description: Non-negotiable product principles every change must respect. globs: alwaysApply: true --- # Constitution — non-negotiables Durable principles for this repository. Design for them from day one; they are not bolt-ons. - **Compliance-by-design.** Encryption in transit and at rest; secrets in a KMS; append-only, hash-chained audit log; Postgres RLS tenant isolation; region pinning; PII/PHI scrubbed from logs. - **MCP / AI-native parity.** Every capability is reachable identically from CLI / API / web / MCP. - **Private-by-default.** Nothing is public, listed, or shared unless explicitly made so. - **Cookieless ingestion on a separate apex.** Ingestion and the CLI tunnel live on `wbhk.my`: cookieless, no CORS, path-token routing, `404` for unknown tokens. Never serve ingestion from a primary application subdomain. - **Standard-Webhooks-native.** Signing/verification follow Standard Webhooks (send and receive). Do not hand-roll signature schemes. - **Open-core boundary.** Open core is Apache-2.0; proprietary code is fenced into `ee/`. Open-core code must not depend on `ee/`. - **Transparent pricing (qualitative).** Keep event metering accurate and single-dimension; never add hidden per-step counters. (No prices or cost figures belong in this repo.) ## Engineering guardrails (non-negotiable) - **Human-UI-testing hard stop.** When a change needs human UI/visual verification you cannot do yourself (rendering, layout, design, interaction, user-facing copy), STOP and explicitly flag it for human testing. Do not mark complete, approve, or merge until a human has verified it. - **Never bypass tests.** Never use `git commit/push --no-verify`; never add `.only`/skip/disable tests or lower coverage thresholds to make CI pass. Fix the root cause. CI required checks are mandatory for everyone (including admins) — status checks have no bypass.
More agent context in webhook-co/webhook
24 other files this repository gives its agents.
AGENTS.md
CLAUDE.md
Cursor rule
Skill
- brainstorming.claude/skills/brainstorming/SKILL.md
- data-migration.claude/skills/data-migration/SKILL.md
- docs-and-api-reference.claude/skills/docs-and-api-reference/SKILL.md
- infra-deploy-runbook.claude/skills/infra-deploy-runbook/SKILL.md
- support-triage.claude/skills/support-triage/SKILL.md
- brainstorming.cursor/skills/brainstorming/SKILL.md
- build-mcp-app.cursor/skills/build-mcp-app/SKILL.md
- build-mcpb.cursor/skills/build-mcpb/SKILL.md
- build-mcp-server.cursor/skills/build-mcp-server/SKILL.md
- data-migration.cursor/skills/data-migration/SKILL.md
- docs-and-api-reference.cursor/skills/docs-and-api-reference/SKILL.md
- infra-deploy-runbook.cursor/skills/infra-deploy-runbook/SKILL.md
- support-triage.cursor/skills/support-triage/SKILL.md
- systematic-debugging.cursor/skills/systematic-debugging/SKILL.md
- test-driven-development.cursor/skills/test-driven-development/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

