Get webhook secret
Returns the current whsec_… signing secret of the endpoint. Requires the write scope: the secret lets its holder sign deliveries, so a read-only key cannot reveal it.
bearerAuthAuthorizationBearer <token>An organization API key (koast_sk_…) with the API surface enabled, or an OAuth access token issued by Koast (koast_at_…) whose audience covers this API. REST access requires an active Agency plan.
endpointId*stringThe webhook endpoint id (ep_…).
1 <= length <= 64Get webhook secret
application/json- response
secret*stringThe current whsec_… signing secret.
previousSecretExpiresAt*|When the previous secret stops being used to sign. Null when no rotation is in progress.
curl -X GET "https://example.com/v1/webhooks/string/secret" \ -H "Authorization: Bearer koast_sk_..."{ "secret": "string", "previousSecretExpiresAt": "string"}Required scope: write. CLI: koast get-webhook-secret, see Webhooks commands. Authentication, headers, errors and pagination work the same on every operation. See Conventions.
Rotate webhook secret
Generates a new signing secret and returns it. For 24 hours deliveries carry signatures from both the new and the previous secret, so receivers can switch without dropping events.
Send webhook test event
Queues a signed ping event for the endpoint, regardless of its event types and brand filter. The outcome appears in its deliveries. A disabled endpoint answers 409 conflict ("Enable the endpoint first.") and nothing is queued.