Rotate a webhook endpoint's signing secret (ADMIN+)
POST
/webhooks/{webhookId}/rotate-secret
const url = 'https://api.invogi.com/v1/webhooks/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/rotate-secret';const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.invogi.com/v1/webhooks/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/rotate-secret \ --header 'Authorization: Bearer <token>'Returns the new secret exactly once. For 24 hours the previous secret keeps signing too, and invogi-signature carries two v1= entries (t=<ts>,v1=<new>,v1=<previous>); receivers should accept a match on either. After that only the new secret is used.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”webhookId
required
string format: uuid
Responses
Section titled “Responses”Secret rotated
Media typeapplication/json
object
id
required
string format: uuid
secret
required
The new signing secret; never shown again
string
previous_secret_expires_at
required
string format: date-time
Example generated
{ "id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "secret": "example", "previous_secret_expires_at": "2026-04-15T12:00:00Z"}Missing or invalid API key
Media typeapplication/json
object
error
required
object
code
required
string
message
required
string
request_id
required
string
Example
{ "error": { "code": "NOT_FOUND" }}API key lacks required scope/role
Media typeapplication/json
object
error
required
object
code
required
string
message
required
string
request_id
required
string
Example
{ "error": { "code": "NOT_FOUND" }}Resource not found
Media typeapplication/json
object
error
required
object
code
required
string
message
required
string
request_id
required
string
Example
{ "error": { "code": "NOT_FOUND" }}Conflicting idempotency key or resource processing state
Media typeapplication/json
object
error
required
object
code
required
string
message
required
string
request_id
required
string
Example
{ "error": { "code": "NOT_FOUND" }}