Hoppa till innehållet

Create a signing secret

POST/v1/webhooks/{id}/secrets

TypeScript sendora.webhooks.createSecret(webhookId)

Python sendora.webhooks.create_secret(webhook_id)

Key sk_… a server key

Adds a second live secret to the webhook and answers its value once; it is never shown again. From then on every delivery carries one signature per live secret, the newest first, so the receiver can switch to the new secret and the old one can be deleted. A webhook holds at most two live secrets.

Parameters

  • idin pathstring (uuid)required

    The webhook id.

Responses

201The new secret, its value shown this once.

  • secretIdstring (uuid)required
  • createdAtstring (date-time)required
  • secretstringrequired

    The secret itself, shown this once.

Example

{
  "secretId": "5b6c7d8e-9f0a-4b1c-8d2e-3f4a5b6c7d8e",
  "createdAt": "2026-09-20T12:00:00.000Z",
  "secret": "whsec_0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d"
}

Errors

Every error answers error, the code, and message, a sentence for a person. A code that adds fields is shown in full below the table.

CodeStatusMeaning
unauthorized401The key is missing, malformed or revoked.
wrong_token_kind403The key is of the other kind: a server key (sk_) where an account key (ak_) is needed, or the reverse. The message names the kind the operation takes.
not_found404No such webhook of this server.
secret_limit409The webhook already holds two live secrets: one in use and one to roll to. Delete one before creating another.

secret_limit

  • maxintegerrequired

    Live secrets a webhook may hold at once.

Example

{
  "error": "secret_limit",
  "message": "The webhook may hold at most 2 live secrets; delete one before creating another.",
  "max": 2
}