curl --request POST \
--url https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret \
--header 'Authorization: Bearer <token>'const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text){
"id": "wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"created_by": {
"user_id": "<string>",
"email": "<string>"
},
"url": "<string>",
"events": [
"job.needs_input"
],
"status": "active",
"disabled_reason": "manual",
"created_at": "<string>",
"last_delivery_at": "<string>",
"secret": "<string>"
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Rotate a webhook secret
Replace one of your webhooks’ signing secret and return the new one once.
curl --request POST \
--url https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret \
--header 'Authorization: Bearer <token>'const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text){
"id": "wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"created_by": {
"user_id": "<string>",
"email": "<string>"
},
"url": "<string>",
"events": [
"job.needs_input"
],
"status": "active",
"disabled_reason": "manual",
"created_at": "<string>",
"last_delivery_at": "<string>",
"secret": "<string>"
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Details
Details
- Callers: an API key, an MCP OAuth token or a Dashboard session.
- Permission:
jobs:read. - Effect: Creates or changes something.
- Errors:
not_found,webhooks_unavailable, and the errors any request can get.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
a webhook ID: wh_ and 32 lowercase hex digits
"wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
Response
The webhook and its new one-time secret
a webhook ID: wh_ and 32 lowercase hex digits
"wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
The member who made the webhook. Only they can change, test or rotate it, and it carries events for the jobs they can see
Show child attributes
Show child attributes
job.needs_input, job.input_expiring, job.succeeded, job.failed, job.repairing active, disabled Why a disabled webhook sends nothing: manual (turned off), gone (its receiver answered 410), unreachable (20 failed deliveries in a row) or secret_unreadable (rotate its secret)
manual, gone, unreachable, secret_unreadable a string to be decoded into a Date
a string to be decoded into a Date
The Standard Webhooks signing secret (whsec_…), shown only in this response. Verify each delivery's webhook-signature with it.