> ## Documentation Index
> Fetch the complete documentation index at: https://docs.devhelm.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Assert on a webhook in a test

> Wait for a captured webhook with the TypeScript SDK or the CLI and read the payload

Start the wait, then trigger the code that sends the webhook. The TypeScript SDK and the CLI set `receivedAfter` to the moment of the call, so a request that arrived earlier does not match.

Install the published client and set the same token the CLI reads:

```bash theme={null}
npm install @devhelm/sdk@1.8.0
export DEVHELM_API_TOKEN=dh_live_xxxxxxxx
```

## TypeScript

```typescript theme={null}
import { Devhelm } from "@devhelm/sdk";

const client = new Devhelm({
  token: process.env.DEVHELM_API_TOKEN!,
});

const event = await client.inboxes.wait("<inbox-id>", {
  timeoutMs: 30_000,
  http: { method: "POST", pathPrefix: "/hooks/stripe" },
});

console.log(event.id, event.method, event.path, event.text());
```

`timeoutMs` is milliseconds (default 30000, maximum 120000). `http.method` and `http.pathPrefix` are optional. `event.text()` is the captured body. `event.json()` parses that text.

A token scoped to one organization and workspace needs no extra headers. If the token can see more than one workspace, set `DEVHELM_ORG_ID` and `DEVHELM_WORKSPACE_ID` before you construct the client. See [Authentication](/authentication).

## CLI

```bash theme={null}
devhelm inboxes wait <inbox-id> \
  --timeout-ms 30000 \
  --method POST \
  --path-prefix /hooks/stripe \
  -o json
```

`--timeout-ms` is milliseconds. The command prints the event as JSON, including `id`, `method`, `path`, and `body`.

## REST

The API looks back 60 seconds when you omit `receivedAfter`. Pass `receivedAfter` yourself when you need the same "from this call onward" window the SDK and CLI use.

```bash API theme={null}
curl -X POST "https://api.devhelm.io/api/v1/webhook/inboxes/<inbox-id>/wait" \
  -H "Authorization: Bearer $DEVHELM_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"timeoutMs":30000,"http":{"method":"POST","pathPrefix":"/hooks/stripe"}}'
```

If nothing arrives before the timeout, the wait ends with HTTP 408.

## Next steps

<CardGroup cols={2}>
  <Card title="Verify signatures" icon="key" href="/testing/webhooks/verify-signatures">
    Recompute the HMAC over the raw body bytes.
  </Card>

  <Card title="Run in CI" icon="terminal" href="/testing/webhooks/ci">
    One inbox per run, then delete it.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.