DEVHELM_API_TOKEN. An API key is already scoped to one organization and workspace. See Authentication.
One inbox per run
--name per run. Read id and httpUrl from the create JSON. Point the system under test at httpUrl, start the wait, then trigger the send. --yes skips the delete prompt so the job can finish unattended.
Delete runs even when the wait fails. A later job should not keep reading the previous run’s events.
TypeScript in the job
inboxes.create returns the inbox, including id and httpUrl. Give httpUrl to the sender, then call wait.
Next steps
Assert in a test
Match method and path, and read the body.
Simulate failures
Reply with 500 or a delay from the same inbox.