Rotate a webhook signing secret
Return a replacement signing secret once. The prior secret remains valid briefly for rotation.
POST
/webhook-subscriptions/{subscription_id}/rotate-secretAuthorization
X-API-KeyAPI key · headerrequiredAPI key in format `sk_*`. Scoped to your partner account; server-side use only.
Path parameters
subscription_idstring<uuid>requiredHeader parameters
Idempotency-KeystringrequiredUnique key for safe retries. Reusing a key on the same endpoint returns the original result.
max length 255
Responses
200Subscription with the replacement secret.
idstring<uuid>requiredurlstring<uri>requiredmatches ^https://
event_typesWebhookEventType[]requiredactivebooleanrequiredcreated_atstring<date-time>requiredsecretstringrequiredHMAC signing secret. Returned only in this response — store it securely; it cannot be retrieved again.
400Validation failed.
codeErrorCoderequiredStable machine-readable error vocabulary for v1.
Allowed:
validation_errorstate_conflictenvironment_mismatchunsupported_destinationinvalid_api_keynot_foundrate_limitedextraobjectrequiredStructured details such as field errors or SKU availability.
messagestringrequiredHuman-readable summary.
401Missing, invalid, expired, or environment-mismatched API key.
codeErrorCoderequiredStable machine-readable error vocabulary for v1.
Allowed:
validation_errorstate_conflictenvironment_mismatchunsupported_destinationinvalid_api_keynot_foundrate_limitedextraobjectrequiredStructured details such as field errors or SKU availability.
messagestringrequiredHuman-readable summary.
404No such resource exists for this partner and environment.
codeErrorCoderequiredStable machine-readable error vocabulary for v1.
Allowed:
validation_errorstate_conflictenvironment_mismatchunsupported_destinationinvalid_api_keynot_foundrate_limitedextraobjectrequiredStructured details such as field errors or SKU availability.
messagestringrequiredHuman-readable summary.
429Rate limit exceeded for this API key.
codeErrorCoderequiredStable machine-readable error vocabulary for v1.
Allowed:
validation_errorstate_conflictenvironment_mismatchunsupported_destinationinvalid_api_keynot_foundrate_limitedextraobjectrequiredStructured details such as field errors or SKU availability.
messagestringrequiredHuman-readable summary.
Try it
Server
Authorization
Parameters
Request
curl -X POST "https://api.vault.stashtab.gg/v1/webhook-subscriptions/497f6eca-6276-4993-bfeb-53cbbbba6f08/rotate-secret" \
-H "X-API-Key: YOUR_API_KEY" \
-H "Idempotency-Key: string"const response = await fetch("https://api.vault.stashtab.gg/v1/webhook-subscriptions/497f6eca-6276-4993-bfeb-53cbbbba6f08/rotate-secret", {
method: "POST",
headers: {
"X-API-Key": "YOUR_API_KEY",
"Idempotency-Key": "string"
}
});Response
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"url": "http://example.com",
"event_types": [
"item.intake.completed"
],
"active": true,
"created_at": "2019-08-24T14:15:22Z",
"secret": "string"
}{
"code": "validation_error",
"extra": {},
"message": "string"
}{
"code": "validation_error",
"extra": {},
"message": "string"
}{
"code": "validation_error",
"extra": {},
"message": "string"
}{
"code": "validation_error",
"extra": {},
"message": "string"
}