BioFlow / API docs / rotateWebhookSecret
POST /v1/webhook-endpoints/{endpoint_id}/rotate-secretMint a NEW whsec_ secret (returned once). For 24 hours deliveries carry TWO signatures — the new and the previous secret — so you can roll your verifier without dropping events.
Requires scope: webhooks:write. Plan entitlement: public_api (Creator and Pro).
Consequential operation — send an Idempotency-Key header.
curl "https://app.getbioflow.com/v1/webhook-endpoints/ENDPOINT_ID/rotate-secret" \
-X POST \
-H "Authorization: Bearer bf_live_YOUR_KEY" \
-H "Idempotency-Key: a-unique-id-per-attempt"| Name | In | Type | Required | Description |
|---|---|---|---|---|
endpoint_id | path | string | yes | Endpoint ID from List webhook endpoints |
| Field | Type | Description |
|---|---|---|
endpoint | object | — |
secret | string | The NEW whsec_ signing secret — shown once, store it now |
previous_secret_expires_at | string (ISO 8601) | Until then the old secret also signs (second signature) |
Every response also carries X-Request-Id plus the IETF draft-11 RateLimit / RateLimit-Policy headers.
| Code | Status | Meaning |
|---|---|---|
invalid_request | 400 | The request body or parameters failed validation |
invalid_api_key | 401 | Missing, malformed, unknown, disabled, or expired API key |
insufficient_scope | 403 | The API key was not granted the required scope |
feature_not_enabled | 403 | The workspace plan does not include public API access |
test_key_read_only | 403 | Test-mode keys are restricted to read operations |
rate_limited | 429 | Per-key rate limit exceeded |
quota_exhausted | 429 | Monthly API quota exhausted |
internal_error | 500 | Something went wrong on our side |
All errors are RFC 9457 application/problem+json — branch on code, quote request_id to support. Full registry on the API docs hub; interactive playground in the API reference.