BioFlow / API docs / rotateWebhookSecret

Rotate the signing secret.

POST /v1/webhook-endpoints/{endpoint_id}/rotate-secret
scope: webhooks:writeCreator & Pro plansquota cost: 1send an Idempotency-Key

Mint a NEW whsec_ secret (returned once). For 24 hours deliveries carry TWO signatures — the new and the previous secret — so you can roll your verifier without dropping events.

Requires scope: webhooks:write. Plan entitlement: public_api (Creator and Pro).

Consequential operation — send an Idempotency-Key header.

Try it

Request.

curl "https://app.getbioflow.com/v1/webhook-endpoints/ENDPOINT_ID/rotate-secret" \ -X POST \ -H "Authorization: Bearer bf_live_YOUR_KEY" \ -H "Idempotency-Key: a-unique-id-per-attempt"
Parameters

Path & query parameters.

Parameters accepted by rotateWebhookSecret
NameInTypeRequiredDescription
endpoint_idpathstringyesEndpoint ID from List webhook endpoints
Response

200The endpoint and its new secret (shown once).

Fields of the 200 response for rotateWebhookSecret
FieldTypeDescription
endpointobject
secretstringThe NEW whsec_ signing secret — shown once, store it now
previous_secret_expires_atstring (ISO 8601)Until then the old secret also signs (second signature)

Every response also carries X-Request-Id plus the IETF draft-11 RateLimit / RateLimit-Policy headers.

Errors

What can go wrong here.

Problem codes this operation can return
CodeStatusMeaning
invalid_request400The request body or parameters failed validation
invalid_api_key401Missing, malformed, unknown, disabled, or expired API key
insufficient_scope403The API key was not granted the required scope
feature_not_enabled403The workspace plan does not include public API access
test_key_read_only403Test-mode keys are restricted to read operations
rate_limited429Per-key rate limit exceeded
quota_exhausted429Monthly API quota exhausted
internal_error500Something went wrong on our side

All errors are RFC 9457 application/problem+json — branch on code, quote request_id to support. Full registry on the API docs hub; interactive playground in the API reference.