Docs
Have a token? Manage tokens in the console
POST
/v1/webhooks/endpoints/{endpoint_id}/rotate

A new signing secret, shown this once. The old one keeps signing alongside it for a day, so you can switch without missing a delivery.

Needs scope webhooks:write.

Authorization

bearer
headerAuthorizationBearer <token>

An access token from the identity provider: a person's, or a customer's from the client credentials grant with an API key (docs.inorbit.hr). The gateway verifies it; the audience is iohr-api.

Path Parameters

endpoint_id*string

The endpoint's id, from List webhook endpoints.

Header Parameters

idempotency-key?string

Makes a retry safe: a repeat with the same key and the same body within a day answers what the first call did (with Idempotency-Replayed: true) instead of running again; the same key with another body is 422 unprocessable. 1 to 255 visible characters; a UUID is a good one.

Length1 <= length <= 255

Response Body

iohr.events.v1.RotateSecretResponse

application/json
  1. response

iohr.events.v1.RotateSecretResponse

previous_expires_at*string
secret*string
import { ApiError, Public } from "@inorbithr/sdk";// Reads INORBIT_TOKEN, or INORBIT_KEY_ID and INORBIT_KEY_SECRET.const api = Public.fromEnv();try {  const { value } = await api.events.rotateSecret("<endpoint_id>");  console.log(value);} catch (e) {  if (!(e instanceof ApiError)) throw e;  console.error(`${e.code}: ${e.problem} (request id ${e.raw.requestId})`);}

npm install @inorbithr/sdk. Calls the package's public surface; an operation newer than your package needs the next release or a client generated for your account. The SDKs.

{  "previous_expires_at": "string",  "secret": "string"}