curl --request POST \
--url https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret \
--header 'Authorization: Bearer <token>'const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text){
"id": "wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"created_by": {
"user_id": "<string>",
"email": "<string>"
},
"url": "<string>",
"events": [
"job.needs_input"
],
"status": "active",
"disabled_reason": "manual",
"created_at": "<string>",
"last_delivery_at": "<string>",
"secret": "<string>"
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Rotate a webhook's signing secret
Replace one of your webhooks’ signing secret and return the new one once. For 24 hours each delivery is signed with both secrets (two webhook-signature entries), so the receiver can switch without missing an event; then only the new one signs.
curl --request POST \
--url https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret \
--header 'Authorization: Bearer <token>'const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/webhooks/{id}/rotate-secret"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text){
"id": "wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"created_by": {
"user_id": "<string>",
"email": "<string>"
},
"url": "<string>",
"events": [
"job.needs_input"
],
"status": "active",
"disabled_reason": "manual",
"created_at": "<string>",
"last_delivery_at": "<string>",
"secret": "<string>"
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
a webhook ID: wh_ and 32 lowercase hex digits
"wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
Response
The webhook and its new one-time secret
a webhook ID: wh_ and 32 lowercase hex digits
"wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
The member who made the webhook: only they change, test and rotate it, and it carries the events of the jobs they could see
Show child attributes
Show child attributes
job.needs_input, job.input_expiring, job.succeeded, job.failed active, disabled Why a disabled webhook sends nothing: manual (turned off), gone (its receiver answered 410), unreachable (20 failed deliveries in a row) or secret_unreadable (rotate its secret)
manual, gone, unreachable, secret_unreadable a string to be decoded into a Date
a string to be decoded into a Date
The Standard Webhooks signing secret (whsec_…), shown in this answer only. Verify each delivery's webhook-signature with it.