Rotate an endpoint's signing secret
curl --request POST \
--url https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret \
--header 'Authorization: Bearer <token>' \
--header 'business-id: <business-id>'import requests
url = "https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret"
headers = {
"business-id": "<business-id>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'business-id': '<business-id>', Authorization: 'Bearer <token>'}
};
fetch('https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"business-id: <business-id>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("business-id", "<business-id>")
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret")
.header("business-id", "<business-id>")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["business-id"] = '<business-id>'
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"consecutive_failures": 123,
"created": "2023-11-07T05:31:56Z",
"enabled": true,
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"label": "<string>",
"last_delivery_at": "2023-11-07T05:31:56Z",
"last_error": "<string>",
"signing_secret": "<string>",
"subscribed_events": [
"<string>"
],
"url": "<string>"
}{
"detail": "<string>",
"code": "<string>"
}{
"detail": "<string>",
"code": "<string>"
}{
"detail": "<string>",
"code": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"ctx": {},
"input": "<unknown>"
}
]
}{
"detail": "<string>",
"code": "<string>"
}webhooks
Rotate an endpoint's signing secret
Issues a new signing secret and returns it. The previous secret stops verifying immediately and there is no overlap window, so deploy the new one to your receiver before rotating. The business is taken from the business-id header rather than the URL; the path-scoped form of this operation is deprecated.
POST
/
api
/
v1
/
webhook-endpoints
/
{endpoint_id}
/
rotate-secret
Rotate an endpoint's signing secret
curl --request POST \
--url https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret \
--header 'Authorization: Bearer <token>' \
--header 'business-id: <business-id>'import requests
url = "https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret"
headers = {
"business-id": "<business-id>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'business-id': '<business-id>', Authorization: 'Bearer <token>'}
};
fetch('https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"business-id: <business-id>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("business-id", "<business-id>")
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret")
.header("business-id", "<business-id>")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.izap.ai/api/v1/webhook-endpoints/{endpoint_id}/rotate-secret")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["business-id"] = '<business-id>'
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"consecutive_failures": 123,
"created": "2023-11-07T05:31:56Z",
"enabled": true,
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"label": "<string>",
"last_delivery_at": "2023-11-07T05:31:56Z",
"last_error": "<string>",
"signing_secret": "<string>",
"subscribed_events": [
"<string>"
],
"url": "<string>"
}{
"detail": "<string>",
"code": "<string>"
}{
"detail": "<string>",
"code": "<string>"
}{
"detail": "<string>",
"code": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"ctx": {},
"input": "<unknown>"
}
]
}{
"detail": "<string>",
"code": "<string>"
}Authorizations
Personal access token (izap_pat_…) sent as Authorization: Bearer ; dashboard session JWTs are also accepted.
Headers
UUID of the business the request is scoped to. Required on this route; the deprecated /businesses/{business_id}/... form takes it from the path instead.
Path Parameters
Response
Successful Response
WebhookEndpointOut plus the one-time secret. Returned by create and rotate only.