API referenceWebhooks

Rotate webhook secret

Generates a new signing secret and returns it. For 24 hours deliveries carry signatures from both the new and the previous secret, so receivers can switch without dropping events.

POST
/v1/webhooks/{endpointId}/rotate-secret
bearerAuth
headerAuthorizationBearer <token>

An organization API key (koast_sk_…) with the API surface enabled, or an OAuth access token issued by Koast (koast_at_…) whose audience covers this API. REST access requires an active Agency plan.

endpointId*string

The webhook endpoint id (ep_…).

Length1 <= length <= 64
Idempotency-Key?string

Retrying with the same key within 24 hours returns the first response without acting again.

Lengthlength <= 255

Response Body

Rotate webhook secret

application/json
  1. response
secret*string

The current whsec_… signing secret.

previousSecretExpiresAt*|

When the previous secret stops being used to sign. Null when no rotation is in progress.

curl -X POST "https://example.com/v1/webhooks/string/rotate-secret" \  -H "Authorization: Bearer koast_sk_..."
{  "secret": "string",  "previousSecretExpiresAt": "string"}

Required scope: write. CLI: koast rotate-webhook-secret, see Webhooks commands. Authentication, headers, errors and pagination work the same on every operation. See Conventions.