v1

latestOpenAPI 3.1.02026-07-2665164286.3 KB
Webhooks

Rotate Webhook Signing Secret

Generates a new signing secret for a webhook endpoint and immediately invalidates the old one. Store the new secret securely — it will not be shown again.

post/v3/webhooks/endpoints/{endpoint_id}/rotate-secret

Path parameters

endpoint_idstring required

Webhook endpoint ID

Headers

Idempotency-Keystring

Optional client-supplied key for safely retrying mutations. Subsequent calls within 24 hours that share this key replay the original response — even if the request body differs slightly (a warning is logged). A retry that arrives while the original is still in flight gets a 409 request_in_progress. Keys must be 1–255 characters from [A-Za-z0-9_:.-]; a UUID is a safe default. Scope is per-endpoint and per-resource: the same key on a different route or path parameter is independent.

Response

Successful response

Example response

{
  "data": {
    "endpoint_id": "ep_abc123def456",
    "secret": "whsec_new_abc123def456"
  }
}