Skip to content
Sendtier Docs
API reference

Rotate a webhook signing secret

Source: OpenAPI (openapi/openapi.yaml).

curl -X POST "https://api.sendtier.example/webhooks/string/rotate-secret" \  -H "Authorization: Bearer st_live_REPLACE_ME"
{  "id": "string",  "url": "string",  "events": [    "email.queued"  ],  "test_mode": true,  "signing_secret": "string",  "created_at": "2019-08-24T14:15:22Z"}
POST
/webhooks/{webhook_id}/rotate-secret

Requires a full-scope API key or dashboard owner, admin or developer. Returns the new signing_secret once; idempotent replays omit it. The previous secret stays valid for 24 hours after it stops being current. Deliveries are signed with both secrets until that expiry, then only with the new secret. A second rotation during the overlap returns 400 invalid_request and does not replace the previous secret.

Authorization

headerAuthorizationBearer <token>

API key: st_live_... or st_test_...

Path Parameters

webhook_id*string

Header Parameters

Idempotency-Key?string

Repeated POST with the same key within 24 h returns the first response.

Lengthlength <= 255

Response Body

Secret rotated. signing_secret is omitted on idempotent replay.

application/json
  1. response
id*string
url*string
events*array<>
test_mode*boolean

True for a test endpoint, created with a test key or in dashboard test mode. A test endpoint receives only test-mode events and a live endpoint only live events. Every payload carries the same test_mode value. The mode cannot change after creation.

signing_secret?string

Present only in the first successful create or rotate-secret response; omitted on idempotent replay.

created_at*string
Formatdate-time