Firsty

Search...

Search...

Management

Rotate a webhook endpoint's signing secret

Experimental. This endpoint is still settling — its request and response shape may change without a deprecation cycle.

Replaces the endpoint's signing secret and returns the new one, the only time it is shown. The new secret signs the next attempt to the endpoint, retries included, so update the consumer first if it verifies signatures.

post/management/webhooks/{webhookEndpointReference}/rotate-secret

Authorization

Authorization: Bearer {token} — an OAuth2 access token from the client-credentials flow. How authentication works

Path parameters

webhookEndpointReferencestringrequired

Webhook endpoint reference, as returned by GET /management/webhooks.

Responses

200The endpoint, with its new signing secretapplication/json
Show response body
dataobjectrequired
Show properties
webhookEndpointReferencestringrequired

Identifies the endpoint in GET /management/webhooks/{webhookEndpointReference}/deliveries.

urlstring · urirequired

Destination Firsty posts events to.

eventTypesarray of stringrequired

Event types delivered to this endpoint. Values this client subscribed to before an event type was retired are returned as stored, so an entry may be absent from GET /catalog/webhook-event-types.

descriptionstring | nullrequired

Free-text label for the endpoint.

activebooleanrequired

Whether events are delivered to this endpoint.

createdAtstring · date-timerequired
updatedAtstring · date-timerequired
signingSecretstringrequired

Key that signs every delivery to this endpoint. Returned only by create and rotate-secret.

401Unauthorized - missing or invalid API key404Resource not found429Rate limit exceeded500Internal server error