Rotate the signing secret (returned once)

Rotates the subscription's signing secret, advances configurationGeneration, cancels
pending deliveries, and returns the new secret exactly once. New test/new-event attempts
carry both new and previous v1 signatures during the 72-hour grace window; either verifies.
A non-immediate rotation during grace returns 409 WebhookSecretRotationInProgress.
Body {immediate:true} revokes all predecessors and emits only the new signature after commit.
Concurrent calls capture the observed generation before serialization; a stale loser returns
the same 409 rather than rotating twice. Pending events are recovered through
/v3/platform/events rather than re-signed. Idempotency-Key is required and its
fingerprint includes the request body. Secret bytes are never response-cached: a
same-key/same-body replay returns 409 ResourceConflict with this subscription in
Location. If the original response was lost, submit a new key with immediate: true; this
revokes the unseen secret and returns a replacement.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required
Body Params
boolean
required

When true, skips the 72-hour grace window and revokes every previous secret immediately.

Headers
string
required
length between 1 and 255
^[\x21-\x7e]{1,255}$

REQUIRED idempotency token for money-moving requests (e.g. transfers). The token is used by the API so a retry after a 5xx/timeout replays the original result instead of moving funds twice. Reuse the same key to retry safely; use a NEW key to issue a genuinely new transfer. Use 1-255 printable ASCII characters.

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json