Rotate the signing secret

POST/api/v1/webhooks/{id}/rotate-secret
Scope: webhooks:manageIdempotency-Key supported

Issues a new signing secret and returns it ONCE. The old secret stops working immediately; deliveries signed with the new one will fail until your receiver is updated, then go through on retry. Requires the "webhooks:manage" scope.

Path parameters#

FieldTypeDescription
idrequired
string

Awrora id (UUID) for the endpoint.

Headers#

FieldTypeDescription
Idempotency-Key
string≥ 8 chars · ≤ 200 chars

Optional. A unique key, 8-200 characters. Retrying with the same key replays the first response verbatim instead of acting twice.

Example request#

bash

curl -X POST "https://your-site.awrora.app/api/v1/webhooks/id_8f2k3n/rotate-secret" \
  -H "Authorization: Bearer $AWRORA_API_KEY"

Responses#

  • 200The endpoint, with its new signing secret.
  • 401Missing, invalid, revoked or expired API key — codes "api_key_missing", "api_key_invalid", "api_key_revoked", "api_key_expired".
  • 403The API app is off, the plan does not include the API, or the key lacks the required scope — codes "app_not_enabled", "plan_upgrade_required", "insufficient_scope" (the last carries "required_scope").
  • 404No such resource. The same response is returned for a resource that belongs to another organization — code "not_found".
  • 429Rate limit exceeded — code "rate_limited". See the x-ratelimit-* headers.
  • 500Something went wrong on our side — code "internal_error".

Response 200

FieldTypeDescription
idrequired
string

Awrora id (UUID) for the endpoint.

urlrequired
string

The https URL deliveries are POSTed to.

descriptionrequired
string | null

Free-text note, or null.

eventsrequired
string[]

The event types this endpoint receives. Test deliveries ignore this list.

statusrequired
string

enabled = receiving; disabled = turned off by the merchant; auto_disabled = turned off by Awrora after 72 hours without a successful delivery. PATCH status back to "enabled" to resume — that also resets the failure counter.

"enabled""disabled""auto_disabled"
sourcerequired
string

"api" when created through this API, "admin" when created in Awrora.

"admin""api"
consecutive_failuresrequired
integermin -9007199254740991 · max 9007199254740991

Failed deliveries in a row. Reset to zero by the next success.

last_success_atrequired
string | null

ISO 8601 with offset, or null.

last_failure_atrequired
string | null

ISO 8601 with offset, or null.

created_atrequired
string

ISO 8601 timestamp with offset.

updated_atrequired
string

ISO 8601 timestamp with offset.

secretrequired
string

The signing secret ("whsec_…"). Shown ONCE, here. Store it now — it cannot be read back, only rotated.

200 response

{
  "id": "res_8f2k3n",
  "url": "https://example.com/webhooks/awrora",
  "description": "string",
  "events": [
    "string"
  ],
  "status": "enabled",
  "source": "admin",
  "consecutive_failures": -9007199254740991,
  "last_success_at": "string",
  "last_failure_at": "string",
  "created_at": "string",
  "updated_at": "string",
  "secret": "string"
}