Webhooks
Rotate the signing secret
Issues a new signing secret and returns it once. The previous secret stops verifying immediately, so deploy the new one before the next event.
Required permission: `webhooks:write`
Accepts `profileId` to target a specific profile. Omit it to use the key’s home profile.
POST
/v1/webhooks/{id}/rotate-secretwebhooks:writeRequest
Authorization
Send your API key as a Bearer token in the Authorization header.
Path parameters
idstringrequiredWebhook subscription id.
Request body
profileIdstringoptionalProfile to act on. Defaults to the profile the API key was created in.
Response
Returns 200.
idstringrequiredsecretstringrequiredShown once. Use it to verify the CuteDyno-Signature header.
Errors
Failures use the standard error format.
| Status | Code | When it happens |
|---|---|---|
| 401 | invalid_api_key | The key does not exist, was revoked, or is malformed. Keys start with cdyn_live_. |
| 404 | not_found | The resource does not exist inside the resolved profile. |
| 429 | rate_limit_exceeded | Too many requests for this key. Honour the Retry-After header before retrying. |
| 500 | internal_error | Something failed on our side. Retry with the same Idempotency-Key; report the requestId if it persists. |