v36

OpenAPI 3.1.0raw.githubusercontent.com2026-08-0187270483.0 KB
Webhooks

Get Webhook Secret

Get the current webhook signing secret.

Returns the active secret used to sign outbound webhook deliveries via the bem-signature header. Returns 404 if no secret has been generated for this environment yet.

Use the secret to verify incoming webhook payloads:

  1. Parse bem-signature: t={timestamp},v1={signature}.
  2. Construct the signed string: {timestamp}.{raw request body}.
  3. Compute HMAC-SHA256 of that string using the secret.
  4. Compare the hex digest against v1.
  5. Reject requests where the timestamp is more than a few minutes old.
get/v3/webhook-secret

Response

The request has succeeded.

secretstring required

The signing secret value. Store this securely — it is shown in full only on generation.