Skip to main content
POST
Rotate a webhook secret
For 24 hours each delivery is signed with both secrets (two webhook-signature entries), so your receiver can switch without missing an event.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

id
string
required

a webhook ID: wh_ and 32 lowercase hex digits

Example:

"wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"

Response

The webhook and its new one-time secret

id
string
required

a webhook ID: wh_ and 32 lowercase hex digits

Example:

"wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"

created_by
object
required

The member who made the webhook. Only they can change, test or rotate it, and it carries events for the jobs they can see

url
string
required
events
enum<string>[]
required
Available options:
job.needs_input,
job.input_expiring,
job.succeeded,
job.failed,
job.repairing
status
enum<string>
required
Available options:
active,
disabled
disabled_reason
enum<string> | null
required

Why a disabled webhook sends nothing: manual (turned off), gone (its receiver answered 410), unreachable (20 failed deliveries in a row) or secret_unreadable (rotate its secret)

Available options:
manual,
gone,
unreachable,
secret_unreadable
created_at
string
required

a string to be decoded into a Date

last_delivery_at
string | null
required

a string to be decoded into a Date

secret
string
required

The Standard Webhooks signing secret (whsec_…), shown only in this response. Verify each delivery's webhook-signature with it.