Skip to main content
POST
Rotate a destination's signing secret, with an overlap

Authorizations

Authorization
string
header
required

A hpt_… customer portal token, as Authorization: Bearer. Stored hashed and looked up by its full SHA-256 hash; shown once at issue. The query string (?token=) is not accepted: a token there ends up in request logs and traces. A browser page trades the token for a portalSession cookie with POST /portal/api/session.

Path Parameters

id
string
required

Destination id, scoped to the token's tenant, project, portal and customer: another customer's id answers 404 like one that never existed.

Response

The new secret, shown here and revealable later.

signing_secret
string
required
Pattern: ^whsec_
previous_secret_expires_at
string<date-time>
required