API reference

Webhooks

Rotate the signing secret

Issues a new signing secret and returns it once. The previous secret stops verifying immediately, so deploy the new one before the next event.

Required permission: `webhooks:write`

Accepts `profileId` to target a specific profile. Omit it to use the key’s home profile.

POST/v1/webhooks/{id}/rotate-secretwebhooks:write

Request

Authorization

Send your API key as a Bearer token in the Authorization header.

Path parameters

idstringrequired

Webhook subscription id.

Request body

profileIdstringoptional

Profile to act on. Defaults to the profile the API key was created in.

Response

Returns 200.

idstringrequired
secretstringrequired

Shown once. Use it to verify the CuteDyno-Signature header.

Errors

Failures use the standard error format.

StatusCodeWhen it happens
401invalid_api_keyThe key does not exist, was revoked, or is malformed. Keys start with cdyn_live_.
404not_foundThe resource does not exist inside the resolved profile.
429rate_limit_exceededToo many requests for this key. Honour the Retry-After header before retrying.
500internal_errorSomething failed on our side. Retry with the same Idempotency-Key; report the requestId if it persists.