receivedAfter to the moment of the call, so a request that arrived earlier does not match.
Install the published client and set the same token the CLI reads:
TypeScript
timeoutMs is milliseconds (default 30000, maximum 120000). http.method and http.pathPrefix are optional. event.text() is the captured body. event.json() parses that text.
A token scoped to one organization and workspace needs no extra headers. If the token can see more than one workspace, set DEVHELM_ORG_ID and DEVHELM_WORKSPACE_ID before you construct the client. See Authentication.
CLI
--timeout-ms is milliseconds. The command prints the event as JSON, including id, method, path, and body.
REST
The API looks back 60 seconds when you omitreceivedAfter. Pass receivedAfter yourself when you need the same “from this call onward” window the SDK and CLI use.
API
Next steps
Verify signatures
Recompute the HMAC over the raw body bytes.
Run in CI
One inbox per run, then delete it.