v2

latestOpenAPI 3.1.02026-07-312303692.4 MB
Endpoint

Rotate Endpoint Secret Handler

Rotates the endpoint's signing secret.

The previous secret will remain valid for the specified grace period (default 24 hours).

post/api/v1/app/{app_id}/endpoint/{endpoint_id}/secret/rotate

Path parameters

app_idstring required

The Application's ID or UID.

Example:unique-identifier

The Application's ID or UID.

endpoint_idstring required

The Endpoint's ID or UID.

Example:unique-identifier

The Endpoint's ID or UID.

Headers

idempotency-keystring

The request's idempotency key

Request body

keystring nullable

The endpoint's verification secret.

Format: base64 encoded random bytes optionally prefixed with whsec_. It is recommended to not set this and let the server generate the secret.

gracePeriodSecondsinteger nullable

How long the old secret will be valid for, in seconds.

Valid values are between 0 (immediate expiry) and 7 days. The default is 24 hours.

Example request

{
  "key": "whsec_C2FVsBQIhrscChlQIMV+b5sSYspob7oD"
}

Response

no content