Rotate a webhook signing secret
/webhooks/{webhook_id}/secret-rotationsGenerates a new signing secret for the webhook endpoint.
The previous secret remains valid for overlap_hours (24 hours by default, up to 72). During this period, each delivery carries one signature per active secret.
The new secret is returned only once. Retrying the request with the same Idempotency-Key does not return the secret again.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/webhooks/string/secret-rotations" \ -H "Content-Type: application/json" \ -d '{}'{ "data": { "object": "webhook_secret_rotation", "previous_secret_expires_at": "2019-08-24T14:15:22Z", "secret": "string" }}Replay webhook events POST
Resends, in bulk, events that were already delivered to this webhook endpoint. The selection can be narrowed by `event_ids`, by an `occurred_after`/`occurred_before` time range, and by `event_types`. Only events that occurred before the request was received and are still retained are eligible. The replay is processed asynchronously as an operation with one item per event. Use the `Location` header to track its progress and per-event results. A replay adds new attempts to the existing deliveries; it never creates new deliveries. The request is rejected if no eligible events match the selection.
Events
Next Page