API referenceWebhooks

Get webhook secret

Returns the current whsec_… signing secret of the endpoint. Requires the write scope: the secret lets its holder sign deliveries, so a read-only key cannot reveal it.

GET
/v1/webhooks/{endpointId}/secret
bearerAuth
headerAuthorizationBearer <token>

An organization API key (koast_sk_…) with the API surface enabled, or an OAuth access token issued by Koast (koast_at_…) whose audience covers this API. REST access requires an active Agency plan.

endpointId*string

The webhook endpoint id (ep_…).

Length1 <= length <= 64

Response Body

Get webhook secret

application/json
  1. response
secret*string

The current whsec_… signing secret.

previousSecretExpiresAt*|

When the previous secret stops being used to sign. Null when no rotation is in progress.

curl -X GET "https://example.com/v1/webhooks/string/secret" \  -H "Authorization: Bearer koast_sk_..."
{  "secret": "string",  "previousSecretExpiresAt": "string"}

Required scope: write. CLI: koast get-webhook-secret, see Webhooks commands. Authentication, headers, errors and pagination work the same on every operation. See Conventions.