BioFlow
API Reference

Rotate the signing secret

POST /v1/webhook-endpoints/{endpoint_id}/rotate-secret — Mint a NEW whsec_ secret (returned once). For 24 hours deliveries carry TWO signatures — the new and the…

POST
/v1/webhook-endpoints/{endpoint_id}/rotate-secret

Mint a NEW whsec_ secret (returned once). For 24 hours deliveries carry TWO signatures — the new and the previous secret — so you can roll your verifier without dropping events.

Requires scope: webhooks:write. Plan entitlement: public_api (Creator and Pro).

Consequential operation — send an Idempotency-Key header.

Authorization

AuthorizationBearer <token>

API key (bf_live_… / bf_test_…) as a Bearer token.

In: header

Path Parameters

endpoint_id*string

Endpoint ID from List webhook endpoints

Length1 <= length

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X POST "https://example.com/v1/webhook-endpoints/string/rotate-secret"
{  "endpoint": {    "id": "string",    "url": "string",    "status": "ACTIVE",    "disabled_reason": "string",    "event_types": [      "contact.created"    ],    "consecutive_failures": 0,    "last_success_at": "2019-08-24T14:15:22Z",    "last_failure_at": "2019-08-24T14:15:22Z",    "previous_secret_expires_at": "2019-08-24T14:15:22Z",    "created_at": "2019-08-24T14:15:22Z",    "updated_at": "2019-08-24T14:15:22Z"  },  "secret": "string",  "previous_secret_expires_at": "2019-08-24T14:15:22Z"}