Replace an endpoint's provider signing secret, with an overlap
curl --request POST \
--url https://app.hookie.ai/admin/api/projects/{pid}/webhooks/{id}/rotate-verification-secret \
--header 'Content-Type: application/json' \
--cookie hookie_session= \
--data '
{
"secret": "<string>",
"overlap_hours": 24
}
'const options = {
method: 'POST',
headers: {cookie: 'hookie_session=', 'Content-Type': 'application/json'},
body: JSON.stringify({secret: '<string>', overlap_hours: 24})
};
fetch('https://app.hookie.ai/admin/api/projects/{pid}/webhooks/{id}/rotate-verification-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/admin/api/projects/{pid}/webhooks/{id}/rotate-verification-secret"
payload = {
"secret": "<string>",
"overlap_hours": 24
}
headers = {
"cookie": "hookie_session=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "<string>",
"verification": {
"scheme": "none",
"header": "<string>",
"algorithm": "sha256",
"encoding": "hex",
"prefix": "<string>",
"tolerance_seconds": 123,
"has_secret": true,
"previous_secret_expires_at": "2023-11-07T05:31:56Z"
}
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}Webhooks
Replace an endpoint's provider signing secret, with an overlap
Top-level alias: POST /admin/api/webhooks//rotate-verification-secret. Write role required. For when the provider rolls its signing secret (#210). secret is the provider’s NEW secret; the one it replaces keeps verifying until overlap_hours from now (default 24; 0 retires it at once), so events signed either way are accepted while the provider switches. Rotating again inside an overlap ends the older secret at once. Neither secret is returned or audited; audited as rotate_webhook_verification_secret with the scheme, overlap and deadline.
POST
/
admin
/
api
/
projects
/
{pid}
/
webhooks
/
{id}
/
rotate-verification-secret
Replace an endpoint's provider signing secret, with an overlap
curl --request POST \
--url https://app.hookie.ai/admin/api/projects/{pid}/webhooks/{id}/rotate-verification-secret \
--header 'Content-Type: application/json' \
--cookie hookie_session= \
--data '
{
"secret": "<string>",
"overlap_hours": 24
}
'const options = {
method: 'POST',
headers: {cookie: 'hookie_session=', 'Content-Type': 'application/json'},
body: JSON.stringify({secret: '<string>', overlap_hours: 24})
};
fetch('https://app.hookie.ai/admin/api/projects/{pid}/webhooks/{id}/rotate-verification-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/admin/api/projects/{pid}/webhooks/{id}/rotate-verification-secret"
payload = {
"secret": "<string>",
"overlap_hours": 24
}
headers = {
"cookie": "hookie_session=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "<string>",
"verification": {
"scheme": "none",
"header": "<string>",
"algorithm": "sha256",
"encoding": "hex",
"prefix": "<string>",
"tolerance_seconds": 123,
"has_secret": true,
"previous_secret_expires_at": "2023-11-07T05:31:56Z"
}
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}Authorizations
sessionbearerAuth
The console's sealed session cookie, set by WorkOS AuthKit. Mutating requests also require the X-Requested-With CSRF header.
Path Parameters
Project id (UUID) belonging to the caller workspace.
Webhook id.
Body
application/json