Skip to main content
POST
Replace an endpoint's provider signing secret, with an overlap

Authorizations

hookie_session
string
cookie
required

The console's sealed session cookie, set by WorkOS AuthKit. Mutating requests also require the X-Requested-With CSRF header.

Path Parameters

pid
string
required

Project id (UUID) belonging to the caller workspace.

id
string
required

Webhook id.

Body

application/json
secret
string
required
write-only

The provider's new signing secret. Never returned.

Required string length: 1 - 512
overlap_hours
number
default:24

How long the OLD secret keeps verifying, in hours (at most 30 days). 0 ends it at once.

Required range: 0 <= x <= 720

Response

Rotated. verification.previous_secret_expires_at is the old secret's deadline, or null when overlap_hours was 0.

id
string
required
verification
object
required

An endpoint's signature verification as responses describe it: the scheme and its settings, never the secret.