rotate_secret

POST /api/v1/accounts/:account_id/webhook_subscriptions/:id/rotate_secret

Rotate the signing secret

Replaces the subscription’s signing secret. Deliveries are signed with the new secret straight away, so update your receiver at the same time.

Parameters

Name Type Required Description
account_id Must be a number. Required

Store (account) ID

id Must be a number. Required

Webhook subscription ID

Error Codes

Code Description
401 Unauthorized – invalid or missing API token
404 Store or subscription not found

Returns

Code: 200

The webhook subscription, with its new secret

Name Type Required Description
id Must be a Integer Required

Unique subscription ID

account_id Must be a Integer Required

Parent store ID

events Must be an array of String Required

Events delivered to this URL, or ‘[“*”]` for every event

event Must be a String Required

The event, when there is exactly one (kept for older integrations)

(nil allowed)
target_url Must be a String Required

URL that receives the POST requests

description Must be a String Required

Your own label for the subscription

(nil allowed)
payload_format Must be a String Required

envelope (default) or flat (the bare data object, used by Zapier)

enabled Must be one of: true, false, 1, 0. Required

Whether events are being delivered

disabled_at Must be a String Required

ISO 8601 time the subscription was disabled

(nil allowed)
disabled_reason Must be a String Required

disabled_by_user, failing or blocked_address

(nil allowed)
last_delivery_at Must be a String Required

ISO 8601 time of the most recent delivery attempt

(nil allowed)
last_delivery_status Must be a Integer Required

HTTP status your URL returned on the most recent attempt

(nil allowed)
last_delivery_error Must be a String Required

Why the most recent attempt failed

(nil allowed)
created_at Must be a String Required

ISO 8601 creation timestamp

updated_at Must be a String Required

ISO 8601 last-update timestamp

secret Must be a String Required

Signing secret (whsec_...). Use it to verify the webhook-signature header.