Rotates the subscription's signing secret, advances configurationGeneration, cancels
pending deliveries, and returns the new secret exactly once. New test/new-event attempts
carry both new and previous v1 signatures during the 72-hour grace window; either verifies.
A non-immediate rotation during grace returns 409 WebhookSecretRotationInProgress.
Body {immediate:true} revokes all predecessors and emits only the new signature after commit.
Concurrent calls capture the observed generation before serialization; a stale loser returns
the same 409 rather than rotating twice. Pending events are recovered through
/v3/platform/events rather than re-signed. Idempotency-Key is required and its
fingerprint includes the request body. Secret bytes are never response-cached: a
same-key/same-body replay returns 409 ResourceConflict with this subscription in
Location. If the original response was lost, submit a new key with immediate: true; this
revokes the unseen secret and returns a replacement.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||