Student sandbox: create a temporary URL, send a test request (curl/Postman/your app), then inspect method, headers, and body — practice receiving and verifying webhooks.
Each bin lives in Redis for about 48 hours, then expires. Sign-in is optional; open the page, create a URL, and POST to the address you get.
Use the bin secret to compute HMAC-SHA256 over the raw body and send X-TayJava-Signature (hex). The lab shows whether the signature matches so you can debug.