Public webhook inboxes for agents. Receive OAuth redirects, payment callbacks and CI notifications.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://comiza.lighting/mcp6 tools · 1285mscreate_inboxCreate a public URL that captures any HTTP request sent to it. Use it when you need something outside this session to reach you: an OAuth redirect, a payment provider callback, a CI notification, a webhook you are testing. Returns the URL to hand to the other service. Requests are readable with get…Create a public URL that captures any HTTP request sent to it. Use it when you need something outside this session to reach you: an OAuth redirect, a payment provider callback, a CI notification, a webhook you are testing. Returns the URL to hand to the other service. Requests are readable with get…
| Parameter | Type | Description |
|---|---|---|
| label | string | Optional note to yourself, for example 'stripe test'. |
list_inboxesList the inboxes you currently own, with their URLs and expiry.List the inboxes you currently own, with their URLs and expiry.
No input schema was published for this tool.
wait_for_requestBlock until a request lands in the inbox, then return it. This is the tool to use straight after you have triggered the action that should produce the callback. Returns immediately if something already arrived after the sequence number you pass.Block until a request lands in the inbox, then return it. This is the tool to use straight after you have triggered the action that should produce the callback. Returns immediately if something already arrived after the sequence number you pass.
| Parameter | Type | Description |
|---|---|---|
| inbox_id* | string | — |
| after_seq | integer | Return only requests newer than this sequence number. Use 0 the first time. |
| timeout_seconds | integer | How long to wait. Capped by your tier. |
get_requestsList what has arrived in an inbox, newest last. Returns summaries without bodies. Use get_request for the full contents of one.List what has arrived in an inbox, newest last. Returns summaries without bodies. Use get_request for the full contents of one.
| Parameter | Type | Description |
|---|---|---|
| inbox_id* | string | — |
| after_seq | integer | — |
| limit | integer | — |
get_requestReturn the full method, headers, query string and body of a single captured request. Text bodies come back as text, binary as base64.Return the full method, headers, query string and body of a single captured request. Text bodies come back as text, binary as base64.
| Parameter | Type | Description |
|---|---|---|
| request_id* | string | — |
delete_inboxprivilegedDelete an inbox and everything captured in it.Delete an inbox and everything captured in it.
| Parameter | Type | Description |
|---|---|---|
| inbox_id* | string | — |
6 of 6 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Public webhook inboxes for agents. Receive OAuth redirects, payment callbacks and CI notifications.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.