API reference

POST/v1/webhooks/{id}/rotate-secret

Rotate the signing secret

Issues a new signing secret and returns it once. The previous secret stops verifying immediately, so deploy the new one before the next event.

Required permission: `webhooks:write`

Accepts `profileId` to target a specific profile. Omit it to use the key’s home profile.

Base URL
https://api.cutedyno.com
Permission
webhooks:write
Idempotency
Not applicable. This request has no side effects worth deduplicating.

Request

curl -X POST "https://api.cutedyno.com/v1/webhooks/WEBHOOK_ID/rotate-secret" \
  -H "Authorization: Bearer $CUTEDYNO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "profileId": "profile_a1b2c3d4"
}'

Path parameters

idstringrequired

Webhook subscription id.

Body

profileIdstringoptional

Profile to act on. Defaults to the profile the API key was created in.

Response

Returns 200 with the following body.

idstringrequired
secretstringrequired

Shown once. Use it to verify the CuteDyno-Signature header.

Example

{
  "id": "a1b2c3d4-0000-4000-8000-000000000000",
  "secret": "whsec_2f8a..."
}

Errors

Failures use the standard error envelope. Branch on code, never on the message.

StatusCodeWhen it happens
401invalid_api_keyThe key does not exist, was revoked, or is malformed. Keys start with cdyn_live_.
404not_foundThe resource does not exist inside the resolved profile.
429rate_limit_exceededToo many requests for this key. Honour the Retry-After header before retrying.
500internal_errorSomething failed on our side. Retry with the same Idempotency-Key; report the requestId if it persists.