Skip to main content
POST
Rotate an endpoint's signing secret

Authorizations

Authorization
string
header
required

Personal access token (izap_pat_…) sent as Authorization: Bearer ; dashboard session JWTs are also accepted.

Headers

business-id
string | null
required

UUID of the business the request is scoped to. Required on this route; the deprecated /businesses/{business_id}/... form takes it from the path instead.

Path Parameters

endpoint_id
string<uuid>
required

Response

Successful Response

WebhookEndpointOut plus the one-time secret. Returned by create and rotate only.

consecutive_failures
integer
required
created
string<date-time>
required
enabled
boolean
required
id
string<uuid>
required
label
string
required
last_delivery_at
string<date-time> | null
required
last_error
string | null
required
signing_secret
string
required
subscribed_events
string[]
required
url
string
required