Free tools Windows power users keep installed
One-click scans. No signup required.
No—not in the documented feedback.created webhook payload. FeedbackBasket represents attachments with attachmentCount; the example payload does not contain screenshot URL fields. Screenshot links mentioned in the changelog belong to the CLI feedback APIs, introduced in version 3.12.0 on June 7, 2026, and should not be assumed to be webhook properties.
What the FeedbackBasket webhook contains
The Project Webhooks guide describes signed, asynchronous feedback.created deliveries to one HTTPS endpoint per project. A sample event contains feedback content, optional submitter email and context, timestamps, project metadata, analysis status and an attachment count. The documentation states: “Optional values are present as null. Attachments are represented only by attachmentCount.” See the Project Webhooks guide for the current schema.
| Surface | What is documented | What you can safely build against |
|---|---|---|
feedback.created webhook |
Attachments are represented by attachmentCount; no screenshot URL field is shown. |
Branch on the count, store the event, and process the feedback. Do not construct or guess attachment URLs. |
| CLI feedback APIs | Version 3.12.0, released June 7, 2026, added screenshot attachment links. | Use the CLI/API workflow documented for that release if your account and client support it. This is a separate interface. |
| Agent workflow | The agent guide tells an investigating agent to check screenshot attachment links, page URL and browser/OS details. | Treat those links as information available to that workflow, not evidence that the webhook JSON contains them. |
| Webhook product release | Version 3.35.0, August 18, 2026, added signed new-feedback webhooks with filters, test delivery, retries and recent status. | Use the webhook controls and delivery status features, while following the payload schema in the guide. |
Why the CLI links do not change the webhook payload
FeedbackBasket publishes several distinct interfaces: REST API, MCP, CLI, agent skill and webhooks. A feature added to one interface is not automatically added to the others. The changelog entry for v3.12.0 establishes that CLI feedback APIs can include screenshot attachment links; it does not document a corresponding webhook property.
Therefore, attachmentCount: 1 means that one attachment is associated with the feedback according to the webhook schema. It does not tell your receiver whether that attachment is a screenshot, where it is hosted, whether it is public, or how to download it. The documented materials do not establish a supported webhook-side lookup that converts the count into a URL.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Build a receiver for the documented schema
Read and verify the exact raw request body
FeedbackBasket signs the exact bytes sent to your endpoint. Do not let a JSON parser read and reserialize the body before verification: whitespace, key order and escaping can change the bytes and invalidate an otherwise genuine signature. The guide documents event, delivery, timestamp and signature headers. Header names, digest formatting and the HMAC algorithm should be copied exactly from your project’s webhook settings.
The following Node.js receiver keeps the body raw, makes the header names and digest format explicit configuration, verifies before parsing, and acknowledges quickly. It intentionally requires those settings instead of guessing undocumented header names.
const http = require('http');
const crypto = require('crypto');
const secret = process.env.FB_WEBHOOK_SECRET;
const eventHeader = (process.env.FB_EVENT_HEADER || '').toLowerCase();
const deliveryHeader = (process.env.FB_DELIVERY_HEADER || '').toLowerCase();
const timestampHeader = (process.env.FB_TIMESTAMP_HEADER || '').toLowerCase();
const signatureHeader = (process.env.FB_SIGNATURE_HEADER || '').toLowerCase();
const algorithm = process.env.FB_HMAC_ALGORITHM;
const encoding = process.env.FB_SIGNATURE_ENCODING || 'hex';
if (!secret || !eventHeader || !deliveryHeader || !timestampHeader || !signatureHeader || !algorithm) {
throw new Error('Set the FeedbackBasket secret, four documented header names, and HMAC algorithm');
}
// Replace this with a durable database or queue in production.
const seenDeliveries = new Set();
function equalDigest(rawBody, supplied) {
const expected = crypto.createHmac(algorithm, secret).update(rawBody).digest(encoding);
const a = Buffer.from(expected, 'utf8');
const b = Buffer.from(supplied, 'utf8');
return a.length === b.length && crypto.timingSafeEqual(a, b);
}
const server = http.createServer((req, res) => {
if (req.method !== 'POST') {
res.writeHead(405).end();
return;
}
const chunks = [];
req.on('data', chunk => chunks.push(chunk));
req.on('end', () => {
const rawBody = Buffer.concat(chunks);
const suppliedSignature = req.headers[signatureHeader];
const deliveryId = req.headers[deliveryHeader];
if (typeof suppliedSignature !== 'string' || typeof deliveryId !== 'string' || !equalDigest(rawBody, suppliedSignature)) {
res.writeHead(401).end();
return;
}
let payload;
try {
payload = JSON.parse(rawBody.toString('utf8'));
} catch {
res.writeHead(400).end();
return;
}
if (seenDeliveries.has(deliveryId)) {
res.writeHead(204).end();
return;
}
// Persist the delivery ID and enqueue work atomically in a real service.
seenDeliveries.add(deliveryId);
const eventName = req.headers[eventHeader];
const timestamp = req.headers[timestampHeader];
const attachmentCount = payload.attachmentCount;
console.log({ eventName, deliveryId, timestamp, attachmentCount });
// Return before slow analysis, downloads or screenshot processing.
res.writeHead(204).end();
});
});
server.listen(process.env.PORT || 3000);
Configure the environment variables with the exact names and signature representation shown in FeedbackBasket’s guide. The in-memory Set is only a demonstration; a restart would forget it, so production code must persist delivery IDs.
Make delivery handling idempotent
Use the documented stable delivery ID as your idempotency key. Insert it into durable storage with a uniqueness constraint, or enqueue it in a system that deduplicates keys. If the ID already exists, return a successful response without performing the side effect again. This protects you from retries and from your own process restarting after work was committed.
A practical sequence is:
- Read the raw body and verify the signature.
- Parse JSON only after verification.
- Validate the event type and required values.
- Record the delivery ID and enqueue the payload in one durable operation.
- Return a 2xx response promptly.
- Have a worker perform slow work such as analysis or a separately documented attachment lookup.
Keep webhook secrets, API tokens, MCP keys and session cookies out of browser code, logs, prompts and generated output. FeedbackBasket’s developer guidance explicitly warns against exposing these credentials.
Rank #2
- HTML CSS Design and Build Web Sites
- Comes with secure packaging
- It can be a gift option
Understand timeout and retry behavior
Requests stop after 10 seconds and do not follow redirects. Return a response from the receiver itself; do not redirect the webhook endpoint to another URL. FeedbackBasket retries HTTP 408, 429 and 5xx responses up to five total attempts, with waits of about 1, 5, 25 and 125 minutes.
| Receiver result | Documented behavior | Implementation response |
|---|---|---|
| 2xx | Delivery is accepted. | Only send this after signature verification and durable enqueue or persistence. |
| 408, 429 or 5xx | Up to five total attempts, approximately 1, 5, 25 and 125 minutes apart. | Use when the event was not durably accepted; make processing idempotent. |
| 410 | Retries stop and the endpoint is paused. | Do not return 410 unless you deliberately want delivery disabled while repairing the endpoint. |
| Other non-success responses | Follow the behavior specified in the current webhook guide. | Monitor delivery status and correct the endpoint rather than relying on repeated attempts. |
The platform also blocks private and other disallowed target addresses. Use a publicly reachable HTTPS endpoint and verify that your hosting, firewall and proxy permit FeedbackBasket’s delivery.
If your workflow needs an actual screenshot link
Do not derive a URL from attachmentCount. First decide which FeedbackBasket surface your integration is using. The changelog’s v3.12.0 note is specifically about CLI feedback APIs. The agent guide’s instruction to check screenshot attachment links describes an agent investigation workflow. Neither statement changes the documented webhook JSON.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →If you need a screenshot for a page URL that you already have in your own workflow, capture that page separately. Keep the resulting asset reference in your system alongside the FeedbackBasket delivery ID, and label it as an independently obtained capture. Do not present it as a URL supplied by the webhook.
Test the receiver before enabling production deliveries
- Send a test delivery from the project’s webhook controls and save the exact raw bytes for debugging.
- Verify a valid signature before attempting JSON parsing.
- Change one byte in the body and confirm that verification fails.
- Deliver the same stable delivery ID twice and confirm the second request causes no duplicate side effect.
- Return a controlled 500 response and observe the documented retry schedule.
- Keep normal processing below the 10-second request limit by queueing slow work.
- Check that your endpoint does not issue a redirect and that its hostname is publicly reachable over HTTPS.
- Record
attachmentCountwithout assuming a file type or URL.
Or skip the browser setup
If you have a page URL and want a clean image or PDF without maintaining a headless-browser service, ScreenshotNeo provides a single-request screenshot API. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing result in headers.
For a page URL associated with a feedback workflow, the basic call is:
Rank #3
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://feedbackbasket.com -o shot.webp
See the ScreenshotNeo API documentation for authentication and options. The same request in Python is:
Recommended Free Tools
import requests
r = requests.get('https://api.screenshotneo.com/v1/shot', params={'access_key': 'YOUR_API_KEY', 'url': 'https://feedbackbasket.com'}, timeout=90)
r.raise_for_status()
open('shot.webp', 'wb').write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://feedbackbasket.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot failed: ${res.status}`);
require('fs').writeFileSync('shot.webp', Buffer.from(await res.arrayBuffer()));
ScreenshotNeo also supports full-page and element capture, 12 device presets plus custom viewports, retina scale, dark mode, PDFs with paper and page-range controls, custom CSS and JavaScript, clicks, selector waits, network-idle waits, request blocking, cookies and headers, timezone and geolocation, transparent backgrounds, resizing, selectable cache TTLs, signed image links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, usage reporting and an OpenAPI specification. Its MCP server exposes take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients.
The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is available on every plan. Create a free ScreenshotNeo account to try it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting common failures
Signature checks fail for genuine deliveries
Confirm that verification uses the untouched raw body, the exact secret, the documented HMAC algorithm and the documented signature encoding. Proxies that decompress, normalize or rewrite the request can also change the signed bytes. Log a delivery ID and verification outcome, never the secret.
The same feedback is processed more than once
Your deduplication store is probably in memory, is keyed by a changing value, or records the ID after side effects. Persist the stable delivery ID before enqueueing work and enforce uniqueness at the database or queue layer.
Rank #4
- Brand: Wiley
- Set of 2 Volumes
- A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers
The sender keeps retrying
A timeout, 408, 429 or 5xx tells FeedbackBasket the delivery was not accepted. Return quickly after durable acceptance, check saturation and rate limits, and inspect the endpoint’s recent delivery status. A 410 pauses the endpoint, so check for accidental 410 responses during deployments.
The payload has an attachment count but no URL
That is the documented webhook behavior. Do not treat it as malformed JSON. Use a separately documented CLI or agent workflow when available, or capture a known page URL independently; the webhook guide does not promise screenshot links.
Requests never arrive
Check that the endpoint is HTTPS, publicly reachable, not redirecting, and not resolving to a private or otherwise disallowed address. Confirm that your firewall and reverse proxy accept the sender’s request and preserve the body exactly.
FAQ
Does attachmentCount identify screenshots?
No. The webhook documentation defines it as the attachment representation, not a type indicator or download reference.
Are screenshot attachment links guaranteed in every FeedbackBasket interface?
No. The documented changelog entry is for CLI feedback APIs in v3.12.0. Interface capabilities must be checked separately.
Best Value
Can I safely expose a webhook secret in a frontend to fetch attachments?
No. Keep webhook secrets and other credentials on the server; the developer guidance forbids placing them in browser code, logs, prompts or output.
Frequently Asked Questions
Does attachmentCount identify screenshots?
No. It is the webhook’s attachment count, not a screenshot type or download URL.
Are screenshot links guaranteed in every FeedbackBasket interface?
No. The documented links were added to CLI feedback APIs in v3.12.0; the webhook schema remains separate.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsCan a webhook secret be used in frontend code?
No. Keep it server-side and out of browser code, logs, prompts and output.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

