What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
No—not in the documented feedback.created webhook payload. FeedbackBasket represents attachments with an attachmentCount value, not screenshot URL fields. The changelog separately mentions screenshot attachment links for CLI feedback APIs in version 3.12.0 (June 7, 2026), but that does not mean those links are delivered in webhooks.
What the webhook sends today
FeedbackBasket sends signed feedback.created events asynchronously to one HTTPS endpoint per project. The example payload includes the feedback content, optional submitter email and context, timestamps, project metadata, analysis status, and an attachment count.
The Project Webhooks guide states: “Optional values are present as null. Attachments are represented only by attachmentCount.” In practical terms, a receiver can learn that a report has attachments, but it cannot read a screenshot URL from the documented webhook JSON.
| Data point | Documented in the webhook payload | What your receiver can do |
|---|---|---|
| Attachment presence | attachmentCount |
Branch when the count is greater than zero |
| Screenshot URL | Not documented | Do not read or construct a URL from the webhook |
| Feedback details | Content and documented optional fields | Store and process the report normally |
| Delivery identity | Stable delivery ID header | Use it as an idempotency key |
Why the CLI changelog entry does not change webhook behavior
FeedbackBasket’s changelog says that CLI feedback APIs began including screenshot attachment links in v3.12.0, released June 7, 2026. That is a statement about the CLI API response. It is not a statement that the project webhook schema gained a screenshot field.
Recommended Free Tools
#1 Best Overall
These are separate software interfaces. FeedbackBasket groups its REST API, MCP server, CLI, agent skill, and webhooks as distinct developer surfaces. A property documented for one surface should not be assumed to exist in another. Unless the webhook guide adds a URL field, treat the webhook contract as count-only.
The agent guide tells an investigating agent to check screenshot attachment links, the page URL, and browser and operating-system details. That indicates screenshot links may be available through another product workflow. It does not document a supported webhook-side lookup or a URL you can derive from attachmentCount.
Build the receiver around the documented contract
1. Accept the raw request body
Signature verification must use the exact bytes FeedbackBasket sent. Do not parse JSON and then serialize it again before checking the signature; whitespace, escaping, and property ordering can change the bytes.
2. Verify the signed request
The guide documents event, delivery, timestamp, and signature headers. Keep the webhook secret on your server, and configure your code with the exact header names, HMAC algorithm, and signature encoding shown in the current guide.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesRank #2
3. Deduplicate by delivery ID
FeedbackBasket supplies a stable delivery ID so your application can recognize retries. Record that ID in durable storage before performing a non-idempotent action. An in-memory set is suitable only for a local demonstration.
4. Parse and branch on attachmentCount
After authentication and deduplication, parse the JSON. If the count is zero, process the report without attachment work. If it is positive, mark the report as having attachments and route it to a workflow that can inspect them through a separately documented FeedbackBasket surface. Do not manufacture screenshot URLs.
5. Return quickly
Webhook requests stop after 10 seconds, and FeedbackBasket does not follow redirects. Verify, enqueue, and acknowledge promptly; perform slow analysis in a worker.
Runnable Node.js receiver
The example below preserves the raw body and leaves provider-specific header names and cryptographic settings configurable. Set those values to the exact names and formats in the FeedbackBasket Project Webhooks guide.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
import express from "express";
import crypto from "node:crypto";
const app = express();
const port = process.env.PORT || 3000;
const secret = process.env.FEEDBACKBASKET_WEBHOOK_SECRET;
const signatureHeader = process.env.FB_SIGNATURE_HEADER;
const deliveryHeader = process.env.FB_DELIVERY_HEADER;
const eventHeader = process.env.FB_EVENT_HEADER;
const timestampHeader = process.env.FB_TIMESTAMP_HEADER;
const hmacAlgorithm = process.env.FB_HMAC_ALGORITHM;
const signatureEncoding = process.env.FB_SIGNATURE_ENCODING || "hex";
if (!secret || !signatureHeader || !deliveryHeader || !hmacAlgorithm) {
throw new Error("Set the webhook secret, header names, and HMAC algorithm first");
}
// Capture bytes, not a parsed object.
app.post("/feedbackbasket/webhook", express.raw({ type: "application/json" }), (req, res) => {
const raw = req.body;
const supplied = req.headers[signatureHeader.toLowerCase()];
const deliveryId = req.headers[deliveryHeader.toLowerCase()];
if (typeof supplied !== "string" || typeof deliveryId !== "string") {
return res.status(400).send("Missing required webhook headers");
}
const expected = crypto
.createHmac(hmacAlgorithm, secret)
.update(raw)
.digest(signatureEncoding);
const a = Buffer.from(supplied);
const b = Buffer.from(expected);
if (a.length !== b.length || !crypto.timingSafeEqual(a, b)) {
return res.status(401).send("Invalid signature");
}
// Replace this with a durable database lookup and insert.
// The delivery ID is the idempotency key.
const alreadyProcessed = false;
if (alreadyProcessed) return res.status(200).send("Already processed");
let event;
try {
event = JSON.parse(raw.toString("utf8"));
} catch {
return res.status(400).send("Invalid JSON");
}
const count = Number(event.attachmentCount || 0);
const job = {
deliveryId,
eventName: eventHeader ? req.headers[eventHeader.toLowerCase()] : undefined,
timestamp: timestampHeader ? req.headers[timestampHeader.toLowerCase()] : undefined,
feedback: event,
hasAttachments: count > 0
};
// Enqueue `job` for background processing, then acknowledge.
console.log(JSON.stringify(job));
return res.status(200).send("Accepted");
});
app.listen(port, () => console.log(`Listening on ${port}`));
Install Express with npm install express, provide the environment variables, and replace the demonstration deduplication flag with an atomic database insert keyed by the delivery ID. The code intentionally does not look for screenshotUrl, attachments, or a guessed download endpoint because those properties are not part of the documented webhook example.
Delivery, retry, and endpoint behavior
- FeedbackBasket uses a durable retry queue and a stable delivery ID.
- HTTP 408, 429, and 5xx responses are retried up to five total attempts, with waits of about 1, 5, 25, and 125 minutes.
- HTTP 410 stops retries and pauses the endpoint.
- Requests time out after 10 seconds.
- Redirects are not followed, so configure the final HTTPS endpoint directly.
- The service documents blocking private and other disallowed target addresses; expose a publicly reachable HTTPS receiver that complies with those restrictions.
Because retries can deliver the same event again, acknowledge only after signature verification and durable enqueueing. If your worker fails later, retry the worker job independently rather than asking the webhook sender to repeat an already accepted delivery.
Security requirements
- Keep the webhook secret out of browser code, logs, prompts, and generated output.
- Verify the signature before trusting any event fields.
- Use the exact raw request body for HMAC verification.
- Store the delivery ID and event-processing result so a retry cannot create duplicate tickets, emails, or database records.
- Redact feedback content and submitter data from ordinary request logs.
- Apply your own authorization and network controls before placing processed feedback into internal systems.
FeedbackBasket’s developer guidance also says not to expose access tokens, MCP keys, session cookies, or webhook secrets in browser code, logs, prompts, or output. The same rule applies to any credentials used by a downstream attachment-inspection workflow.
If your workflow needs the actual screenshot
Use a documented FeedbackBasket surface
The v3.12.0 changelog entry establishes screenshot attachment links for CLI feedback APIs. If your team already uses that CLI interface, follow its current documentation for obtaining those links. Do not copy a URL from a CLI response into assumptions about webhook JSON.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #4
Do not infer a URL from the count
attachmentCount: 1 tells you that an attachment exists; it does not identify its filename, storage key, or download address. There is no documented webhook property in the cited guide from which to calculate one.
Keep the two stages separate
A robust design is: receive and verify the webhook, persist the delivery and feedback, then run a separately authorized attachment-inspection job through a supported FeedbackBasket interface. If that interface is unavailable to your account or version, surface the report as “attachment present” rather than pretending the URL is known.
Or skip the browser setup
If what you need is a clean screenshot of a page URL you already have—not a hidden way to extract FeedbackBasket’s attachment links—ScreenshotNeo provides a website screenshot API and MCP server. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; failed bot checks, blank pages, timeouts, failed loads, and cache hits are not billed. Responses identify the page verdict and billing status in X-Page-Verdict and X-Billed headers.
One GET request returns PNG, JPEG, WebP, or PDF. The API supports full-page and selector captures, lazy-image loading, dark mode, device presets, arbitrary viewports, retina scale, PDF page controls, custom CSS and JavaScript, clicks, waits, blocked resources, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, selectable caching TTLs, signed image links, asynchronous jobs with signed webhooks, bulk capture for up to 100 URLs per call, usage reporting, and an OpenAPI specification. An MCP server exposes take_screenshot, get_page_info, and capture_pdf to Claude, Cursor, and other MCP clients.
See the ScreenshotNeo API documentation for parameter details. For example:
Best Value
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Every feature is available on every plan: 1,000 screenshots per month free with no card; Starter is $5 for 3,000, Growth $15 for 15,000, Pro $39 for 60,000, Scale $99 for 250,000, and Business $249 for 1,000,000. Yearly billing provides two months free. Create a free ScreenshotNeo account to start.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Signature checks fail | The body was parsed and reserialized, or the wrong algorithm/encoding is configured | Capture raw bytes and copy the current guide’s cryptographic settings exactly |
| The same feedback is processed twice | No durable idempotency record | Insert the stable delivery ID atomically before side effects |
| No screenshot field appears | The webhook contract exposes only attachmentCount |
Use a separately documented CLI/API workflow; do not infer a URL |
| Sender retries unexpectedly | Your endpoint returned 408, 429, or 5xx, timed out, or redirected | Acknowledge within 10 seconds from the final HTTPS URL after durable enqueueing |
| Endpoint is paused | A 410 response was returned | Restore the endpoint and remove the condition causing 410 before re-enabling delivery |
| Receiver cannot reach the service | Private or otherwise disallowed target address | Use a publicly reachable HTTPS endpoint permitted by the webhook service |
FAQ
Can I add a custom screenshot URL field to the outgoing webhook?
Not through the documented project webhook schema. Treat the payload as provider-defined and use attachmentCount until FeedbackBasket documents a URL property.
Does version 3.12.0 guarantee links in every integration?
No. The changelog describes links in CLI feedback APIs. It does not extend that behavior to webhooks, REST responses generally, or MCP tools.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Should my endpoint return the screenshot to FeedbackBasket?
No. The receiver should verify, deduplicate, enqueue, and acknowledge the event. Attachment retrieval is a separate, authorized workflow.
Frequently Asked Questions
Can I add a custom screenshot URL field to the outgoing webhook?
Not through the documented project webhook schema. Treat the payload as provider-defined and use attachmentCount until FeedbackBasket documents a URL property.
Does version 3.12.0 guarantee links in every integration?
No. The changelog describes links in CLI feedback APIs. It does not extend that behavior to webhooks, REST responses generally, or MCP tools.
Should my endpoint return the screenshot to FeedbackBasket?
No. The receiver should verify, deduplicate, enqueue, and acknowledge the event. Attachment retrieval is a separate, authorized workflow.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

