Uptimely

Rotate a webhook signing secret

POST
/v1/webhook-endpoints/{webhook_endpoint_id}/rotate-secret

Mints a new signing secret and keeps the previous one valid for 24 hours, during which every delivery is signed with BOTH. Roll your verifier inside that window and no event is lost.

Authorization

bearerAuth
AuthorizationBearer <token>

An uptimely_live_ project API key (Settings → API Keys).

In: header

Path Parameters

webhook_endpoint_id*string

Id of the webhook endpoint.

Match^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
Formatuuid

Header Parameters

Idempotency-Key?string

Optional client-generated key (1-255 visible ASCII characters; a UUID works) making this POST safely retryable. Retrying with the SAME key and byte-identical body within 24h replays the stored first response. The same key with a different body answers 422 idempotency_key_reused; a retry racing the first execution answers 409 idempotency_in_progress. Omitting the header executes normally with no idempotency guarantee.

Length1 <= length <= 255

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X POST "https://example.com/v1/webhook-endpoints/497f6eca-6276-4993-bfeb-53cbbbba6f08/rotate-secret"
{  "id": "string",  "secret": "string",  "previous_secret_expires_at": "2019-08-24T14:15:22Z"}