Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
Rotate secret on a webhook endpoint
Replaces the endpoint's signing secret and returns the new one, once (`status.signing_secret`).
Replaces the endpoint's signing secret and returns the new one, once (status.signing_secret). For 24 hours deliveries carry a signature with each secret, so a receiver can switch without dropping one.
- Path
POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/webhook_endpoints/webhook-endpoint:rotateSecret - Scope
events:write - Effect
write— a successful call changes state. - Collection webhook_endpoints
#Request
| Field | Type | What it is |
|---|---|---|
name | string | The name of the webhook endpoint. Required. |
etag | string | Rotate only if the current etag matches. |
#Response
| Field | Type | What it is |
|---|---|---|
name | string | orgs/{org}/projects/{project}/envs/{env}/webhook_endpoints/{webhook_endpoint}. |
uid | string | whe_<cell><ulid>; never reused. Output only. |
meta | ResourceMeta | Resource metadata. |
spec | WebhookEndpointSpec | Desired state. Required. |
status | WebhookEndpointStatus | Observed state. Output only. |
#ResourceMeta
| Field | Type | What it is |
|---|---|---|
generation | int64 | Increases by one on every change to spec. Output only. |
etag | string | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only. |
create_time | timestamp | When the Resource was created. Output only. |
update_time | timestamp | When the Resource last changed. Output only. |
delete_time | timestamp | Set while the Resource is being deleted. Output only. |
labels | map<string, string> | Caller-writable, indexed labels (AIP-122 label rules). |
annotations | map<string, string> | Caller-writable, unindexed annotations. |
display_name | string | Caller-writable human-readable name. |
creator | string | The principal that created the Resource. Output only. |
#WebhookEndpointSpec
| Field | Type | What it is |
|---|---|---|
uri | string | The HTTPS URI deliveries are POSTed to; its host resolves to a public address. Required. |
disabled | bool | Stop delivering; deliveries queue until enabled. |
max_concurrent_deliveries | int32 | At most this many deliveries in flight; default 10. |
event_types | string[] | Which event types the endpoint receives: an exact type (order.paid), a prefix ending in .* (order.*), or * for every type; default ["*"]. |
rate_limit_per_second | int32 | At most this many attempts start per second; 0 is no limit. Deliveries over the limit wait their turn; none is dropped. |
#WebhookEndpointStatus
| Field | Type | What it is |
|---|---|---|
observed_generation | int64 | The generation this status was computed from. Output only. |
conditions | Condition[] | Ready, Reconciling, Stalled. Output only. |
state | WebhookEndpointState | Whether Events is delivering. Output only. One of enabled, disabled, failing_disabled. |
disable_reason | string | Why Events disabled the endpoint, when it did. Output only. |
last_success_time | timestamp | The last 2xx answer. Output only. |
consecutive_failure_count | int32 | Consecutive failed delivery attempts since the last 2xx. Output only. |
signing_secret | string | The Standard Webhooks signing secret (whsec_…). Set only in the answer of CreateWebhookEndpoint and RotateWebhookEndpointSecret; every other read leaves it empty, and Events never shows it again. Output only. Never returned again. |
previous_secret_expire_time | timestamp | After a rotation, deliveries carry a second signature with the previous secret until this time. Output only. |
#Condition
| Field | Type | What it is |
|---|---|---|
type | string | The condition type, for example Ready. |
status | ConditionStatus | Whether the condition holds. One of true, false, unknown. |
observed_generation | int64 | The generation this observation was made against. |
reason | string | A machine-readable UpperCamelCase reason. |
message | string | A customer-safe human-readable message. |
severity | Severity | How severe a FALSE condition is. One of info, warning, error. |
transition_time | timestamp | When status last changed. |
#Errors
UNAUTHENTICATED— No valid key or token was presented.PERMISSION_DENIED— The key lacks the method's permission.RESOURCE_NOT_FOUND— The named Resource does not exist or is not visible.ETAG_MISMATCH— The etag sent does not match the Resource's current etag.IDEMPOTENCY_KEY_REUSED— An Idempotency-Key was reused with another body.IDEMPOTENCY_IN_PROGRESS— The first call with this Idempotency-Key is still running.
Every error arrives in the body Errors describes.
#Examples
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/webhook_endpoints/webhook-endpoint:rotateSecret" \
-H "Authorization: Bearer $SYLPHX_API_KEY" \
-H "Content-Type: application/json" \
-d '{}'