API reference
Change a webhook receiver's secret
POST /v1/webhooks/{receiver_id}/rotate-secret
A new signing secret, in this answer and never again. With keep_previous_for, the old one keeps signing beside it until then — every delivery carries a signature from each — so your receiver can be updated first. now, the default, is the answer to a leak. Needs webhooks:write.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
receiver_id |
path | string (uuid) | Yes |
Body
Sent as JSON. A field this operation does not take is refused, so a typo fails loudly.
| Field | Type | Required | Description |
|---|---|---|---|
keep_previous_for |
one of now, 1h, 24h, 7d |
No | How long the old secret keeps signing beside the new one: now ends it at once, which is the answer to a leak; an overlap lets you update your receiver first. |
Answer
200 with WebhookReceiverWithSecret.
Errors
Every error is a problem document with a stable code.
| Status | When |
|---|---|
401 |
The key is missing, mistyped, unknown, revoked or expired. |
403 |
The key lacks a permission, a live key was sent from a browser, or the organization is frozen and the request would change something. |
404 |
This key reaches no such receiver. |
409 |
The project is frozen. |
422 |
Validation Error |
429 |
Too many requests for this key or its organization; see Retry-After. |
500 |
Something went wrong on our side. Quote the request_id to support. |
Examples
#!/bin/sh
# Change a receiver's secret, keeping the old one for a day
curl -sS --fail-with-body -X POST "https://api.aigently.ai/v1/webhooks/6d8f0a2c-4e6b-4d8f-9a1c-3e5b7d9f1a3c/rotate-secret" \
-H "Authorization: Bearer $AIGENTLY_API_KEY" \
--json '{
"keep_previous_for": "24h"
}'
Try it
Sends this request to the API from your browser, with a test key. Nothing it does rings a phone.