Skip to main content
A webhook testing inbox is a URL that records the HTTP requests your system sends. It is separate from outbound platform webhooks, which deliver DevHelm events to you.

Create an inbox

The JSON includes id, httpUrl, and publicToken. Senders call httpUrl. You use id with devhelm inboxes wait and the TypeScript client.

What gets stored

Send any HTTP method to the inbox URL. A path after the token, such as /hooks/stripe, is stored as the event path. Query parameters are stored with repeated keys kept.
API
Each captured event includes:
  • HTTP method, path, and query
  • Request headers, as received
  • The body as text, up to 256 KB (bodyTruncated when the text view is cut)
  • sha256 of the raw body bytes
The raw body bytes, not a re-serialized JSON document, are what you download to verify a signature. The reply the sender sees is the inbox mock response (status, content type, body, and delay). Change that reply in Simulate a failing receiver.

When a request is dropped

Set the inbox to disabled and new requests are not stored. The sender receives 404.
Turn capture back on with --status active. The inbox records retentionDays (the plan default when you omit it on create). That value is how long captured events are kept.

Next steps

Assert in a test

Wait for the next matching request and read the body.

Webhook Testing API

Inboxes, events, raw bodies, and wait.