Skip to content
Stashtab Vault API
Esc
navigateopen⌘Jpreview

Rotate a webhook signing secret

Return a replacement signing secret once. The prior secret remains valid briefly for rotation.

POST/webhook-subscriptions/{subscription_id}/rotate-secret
Authorization
X-API-KeyAPI key · headerrequired
API key in format `sk_*`. Scoped to your partner account; server-side use only.
Path parameters
subscription_idstring<uuid>required
Header parameters
Idempotency-Keystringrequired
Unique key for safe retries. Reusing a key on the same endpoint returns the original result.
max length 255
Responses
200Subscription with the replacement secret.
idstring<uuid>required
urlstring<uri>required
matches ^https://
event_typesWebhookEventType[]required
activebooleanrequired
created_atstring<date-time>required
secretstringrequired
HMAC signing secret. Returned only in this response — store it securely; it cannot be retrieved again.
400Validation failed.
codeErrorCoderequired
Stable machine-readable error vocabulary for v1.
Allowed:validation_errorstate_conflictenvironment_mismatchunsupported_destinationinvalid_api_keynot_foundrate_limited
extraobjectrequired
Structured details such as field errors or SKU availability.
messagestringrequired
Human-readable summary.
401Missing, invalid, expired, or environment-mismatched API key.
codeErrorCoderequired
Stable machine-readable error vocabulary for v1.
Allowed:validation_errorstate_conflictenvironment_mismatchunsupported_destinationinvalid_api_keynot_foundrate_limited
extraobjectrequired
Structured details such as field errors or SKU availability.
messagestringrequired
Human-readable summary.
404No such resource exists for this partner and environment.
codeErrorCoderequired
Stable machine-readable error vocabulary for v1.
Allowed:validation_errorstate_conflictenvironment_mismatchunsupported_destinationinvalid_api_keynot_foundrate_limited
extraobjectrequired
Structured details such as field errors or SKU availability.
messagestringrequired
Human-readable summary.
429Rate limit exceeded for this API key.
codeErrorCoderequired
Stable machine-readable error vocabulary for v1.
Allowed:validation_errorstate_conflictenvironment_mismatchunsupported_destinationinvalid_api_keynot_foundrate_limited
extraobjectrequired
Structured details such as field errors or SKU availability.
messagestringrequired
Human-readable summary.
Try it
Server
Authorization
Parameters
Request
curl -X POST "https://api.vault.stashtab.gg/v1/webhook-subscriptions/497f6eca-6276-4993-bfeb-53cbbbba6f08/rotate-secret" \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Idempotency-Key: string"
Response
{
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "url": "http://example.com",
  "event_types": [
    "item.intake.completed"
  ],
  "active": true,
  "created_at": "2019-08-24T14:15:22Z",
  "secret": "string"
}