Skip to main content
POST
Rotate a webhook endpoint's secret

Authorizations

Authorization
string
header
required

An organization API key. Keys carry a role (read_write or read_only) and may be restricted to a namespace prefix such as acme/*, or to one namespace such as acme/prod/tenant_1. A prefix matches on a / boundary: acme/prod/tenant_1* covers acme/prod/tenant_1 and everything under acme/prod/tenant_1/, never acme/prod/tenant_12.

Headers

Idempotency-Key
string

Returns the original response verbatim while the node still caches it. Correctness never depends on it.

Minimum string length: 1

Path Parameters

id
string
required
Pattern: ^we_[0-9a-z]{26}$

Body

application/json
previous_valid_for
string
default:24h

How long the old secret keeps signing beside the new one, at most 7d. 0s stops it at once, as after a leak.

Pattern: ^(0|[1-9][0-9]*)[smhd]$

Response

The endpoint with its new secret.

id
string
required
Pattern: ^we_[0-9a-z]{26}$
url
string<uri>
required
description
string
required
events
string[]
required

The platform event types it receives, besides the events of subscriptions that name it.

An event type such as job.completed, or a family with * after the dot, such as job.*.

Maximum string length: 64
Pattern: ^[a-z_]+\.([a-z_]+|\*)$
namespace_prefix
string
required

Which namespaces, written as an API key's scope: * for the whole organization, a prefix such as acme/staging/ or acme/*, or one namespace. A prefix matches on a / boundary.

Required string length: 1 - 257
Pattern: ^(\*|[A-Za-z0-9._:/-]+\*?)$
status
enum<string>
required

active: delivering. failing: no successful delivery for 24 hours and at least 10 failed attempts; still delivering, and owners and admins were emailed. disabled: after 5 days without a success, or by enabled: false; deliveries are skipped until it is enabled.

Available options:
active,
failing,
disabled
failing_since
string<date-time> | null
required

When the current run of failed attempts began, the first failure after the last success; null once an attempt succeeds. Failing and disabled count from it.

max_per_second
number | null
required

The most deliveries a second it is sent; null for no limit beyond 16 in flight at once.

previous_secret_expires_at
string<date-time> | null
required

When the secret before the last rotation stops signing; null when only one secret signs.

stats
object
required
created_at
string<date-time>
required

RFC 3339, UTC.

updated_at
string<date-time>
required

RFC 3339, UTC.

secret
string

On create, on rotation, and on a get with a read_write key; absent otherwise.

Pattern: ^whsec_[A-Za-z0-9+/]{43}=$