Rotate webhook secret
Generates a new signing secret and returns it. For 24 hours deliveries carry signatures from both the new and the previous secret, so receivers can switch without dropping events.
bearerAuthAuthorizationBearer <token>An organization API key (koast_sk_…) with the API surface enabled, or an OAuth access token issued by Koast (koast_at_…) whose audience covers this API. REST access requires an active Agency plan.
endpointId*stringThe webhook endpoint id (ep_…).
1 <= length <= 64Idempotency-Key?stringRetrying with the same key within 24 hours returns the first response without acting again.
length <= 255Rotate webhook secret
application/json- response
secret*stringThe current whsec_… signing secret.
previousSecretExpiresAt*|When the previous secret stops being used to sign. Null when no rotation is in progress.
curl -X POST "https://example.com/v1/webhooks/string/rotate-secret" \ -H "Authorization: Bearer koast_sk_..."{ "secret": "string", "previousSecretExpiresAt": "string"}Required scope: write. CLI: koast rotate-webhook-secret, see Webhooks commands. Authentication, headers, errors and pagination work the same on every operation. See Conventions.
Resend failed webhook deliveries
Re-queues the latest finally failed delivery of each event (at most 100 events from the most recent 500 attempts). Receivers dedupe on the event id.
Get webhook secret
Returns the current whsec_… signing secret of the endpoint. Requires the write scope: the secret lets its holder sign deliveries, so a read-only key cannot reveal it.