Rotate a webhook signing secret
/webhooks/{webhook_id}/secret-rotationsGenerates a new signing secret for the webhook endpoint.
The previous secret remains valid for overlap_hours (24 hours by default, up to 72). During this period, each delivery carries one signature per active secret.
The new secret is returned only once. Retrying the request with the same Idempotency-Key does not return the secret again.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Public ID of the webhook, prefixed with whk_.
Header Parameters
Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9._:-]. Required by this operation: a missing key returns idempotency_key_required, and a malformed key returns idempotency_key_invalid. Repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true.
Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.
length <= 64Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/webhooks/string/secret-rotations" \ -H "Idempotency-Key: string" \ -H "Content-Type: application/json" \ -d '{}'{ "data": { "object": "webhook_secret_rotation", "previous_secret_expires_at": "2019-08-24T14:15:22Z", "secret": "string" }}Replay webhook events POST
Resends, in bulk, events that were already delivered to this webhook endpoint. The selection can be narrowed by `event_ids`, by an `occurred_after`/`occurred_before` time range, and by `event_types`. Only events that occurred before the request was received and are still retained are eligible. The replay is processed asynchronously as an operation with one item per event. Use the `Location` header to track its progress and per-event results. A replay adds new attempts to the existing deliveries; it never creates new deliveries. The request is rejected if no eligible events match the selection.
Events2
Next Page