body text can differ from those bytes once it is decoded or truncated. Download the raw body and hash that.
The signature the sender attached is on the event headers. Compare your HMAC to that header using the scheme the sender documents (hex, base64, or a t=...,v1=... value).
CLI
Wait for the event, then download its raw body.--file is required.
sha256 on the event is the SHA-256 of those same raw bytes. It is not the HMAC.
TypeScript
event.raw() downloads the raw body. event.headers is the header map as received, so you can read the signature header next to the MAC.
Next steps
Assert in a test
Wait for the request before you check the signature.
Webhook Testing API
Event fields, including headers and the raw download.