Skip to main content
POST
Rotate a webhook endpoint's signing secret

Authorizations

x-api-key
string
header
required

Headers

Idempotency-Key
string
required

Caller-generated unique key that lets the server safely replay this request. The original response is returned for 30 days on any retry with the same key from the same organization. Required on every state-changing money-moving or resource-creating POST.

Required string length: 1 - 128
Pattern: ^[A-Za-z0-9_.:-]{1,128}$
Example:

"01J7B3K2X9M8N5P6Q7R8S9T0V1"

Path Parameters

id
string
required
Example:

"wep_1A2b3C4d5E6f7G8h9I0jKl"

Response

id
string
required

Unique webhook endpoint identifier

Pattern: ^wep_[0-9A-Za-z]{22}$
url
string
required

URL where webhook payloads are delivered

Example:

"https://api.example.com/webhooks/conduit"

description
string | null
required

Human-readable description of this endpoint's purpose

Example:

"Production webhook receiver"

status
enum<string>
required

Whether this endpoint is currently receiving new deliveries. When disabled, the endpoint is excluded from event fan-out — no new deliveries are enqueued. In-flight (already-enqueued) deliveries are not cancelled and continue retrying per the normal schedule. Set back to active via PATCH to resume receiving new deliveries.

Available options:
active,
disabled
subscription
object
required

Event subscription configuration for this endpoint

createdAt
string<date-time>
required

ISO 8601 timestamp

Example:

"2026-01-15T09:30:00.000Z"

updatedAt
string<date-time>
required

ISO 8601 timestamp

Example:

"2026-01-15T09:30:00.000Z"

secret
string
required

Per-endpoint signing secret. Returned only once — when the endpoint is created and again each time its secret is rotated — so store it securely. Format: literal whsec_ prefix + 64 hex chars (see signature.secretFormat). Pass the FULL string verbatim, including the whsec_ prefix, as the HMAC-SHA256 key when verifying incoming X-Conduit-Signature headers — stripping the prefix produces a different digest and every valid delivery fails verification.

Example:

"whsec_8f3a2b1c4d5e6f7081928374a5b6c7d8e9f0a1b2c3d4e5f60718293a4b5c6d7e"

signature
object
required

Signature verification metadata. Same constants apply to every webhook delivery; signing secrets are per-endpoint.