Skip to content
Norbelys
Esc
↑↓navigate↵open⌘Jpreview

Rotate an endpoint's signing secret. The new secret is in this response only; the old one keeps signing for 24 hours, so every attempt carries both signatures meanwhile.

POST/v1/webhook_endpoints/{id}/rotate_secret
Authorization
AuthorizationBearer token · headerrequired

An API key (nb_live_…, nb_test_…), a workspace token (nbs_…) or a CLI token (nbc_…).

Path parameters
idId_WebhookEndpointrequired

The endpoint id (whe_…).

matches ^whe_[0-9a-f]{32}$
Header parameters
Idempotency-Keystringrequired

A stable key for this logical request; reuse it when retrying.

min length 1 · max length 128 · matches ^[!-~]+$
Responses
200

The endpoint, with its new secret shown once.

created_atTimestamprequired
disabled_reasonstring | null

gone (it answered 410), failing (5 days without a success) or manual. New values may be added.

enabledbooleanrequired

False once disabled, by a person or by its failures.

event_typesstring[]required

The event types the endpoint receives.

failing_sinceTimestamp | null
Show properties
One of:
Timestamp
string<date-time>
null
null
idId_WebhookEndpointrequired
matches ^whe_[0-9a-f]{32}$
secretstring | null

The signing secret, shown only when the endpoint is created or its secret rotated.

updated_atTimestamprequired
urlstringrequired
versioninteger<int64>required

The endpoint's version, also the response's ETag: updated_at in microseconds since the Unix epoch. An update sent with it in If-Match applies only to this version, so a replaced list of event types never undoes a change made since it was read. A failure or a disabling by the worker moves it too.

401

No valid credential.

codestringrequired

The code from the closed registry; programs branch on it, never on the text. New codes may be added.

detailstringrequired

What went wrong, for a person; never an internal cause.

errorsFieldError[]

With validation_failed only: every invalid field.

Show properties
Array of FieldError
codestringrequired

What is wrong (required, range, length, format, invalid, …).

detailstringrequired

A safe, human-readable explanation.

pointerstringrequired

RFC 6901 pointer into the body, or ?name for a query parameter.

instancestringrequired

The request's path.

request_idstringrequired

The request's id, also in X-Request-Id: what support needs to find the request.

retry_afterinteger<int64> | null

With 429 and 503: the seconds to wait, as in Retry-After.

min 0
statusinteger<int32>required

The HTTP status.

min 0
titlestringrequired

Fixed per code.

typestringrequired

https://docs.norbelys.com/errors/<code>, a page that explains the code.

403

The credential lacks automation:manage.

codestringrequired

The code from the closed registry; programs branch on it, never on the text. New codes may be added.

detailstringrequired

What went wrong, for a person; never an internal cause.

errorsFieldError[]

With validation_failed only: every invalid field.

Show properties
Array of FieldError
codestringrequired

What is wrong (required, range, length, format, invalid, …).

detailstringrequired

A safe, human-readable explanation.

pointerstringrequired

RFC 6901 pointer into the body, or ?name for a query parameter.

instancestringrequired

The request's path.

request_idstringrequired

The request's id, also in X-Request-Id: what support needs to find the request.

retry_afterinteger<int64> | null

With 429 and 503: the seconds to wait, as in Retry-After.

min 0
statusinteger<int32>required

The HTTP status.

min 0
titlestringrequired

Fixed per code.

typestringrequired

https://docs.norbelys.com/errors/<code>, a page that explains the code.

404

No such endpoint in this workspace.

codestringrequired

The code from the closed registry; programs branch on it, never on the text. New codes may be added.

detailstringrequired

What went wrong, for a person; never an internal cause.

errorsFieldError[]

With validation_failed only: every invalid field.

Show properties
Array of FieldError
codestringrequired

What is wrong (required, range, length, format, invalid, …).

detailstringrequired

A safe, human-readable explanation.

pointerstringrequired

RFC 6901 pointer into the body, or ?name for a query parameter.

instancestringrequired

The request's path.

request_idstringrequired

The request's id, also in X-Request-Id: what support needs to find the request.

retry_afterinteger<int64> | null

With 429 and 503: the seconds to wait, as in Retry-After.

min 0
statusinteger<int32>required

The HTTP status.

min 0
titlestringrequired

Fixed per code.

typestringrequired

https://docs.norbelys.com/errors/<code>, a page that explains the code.

Try it
Server
Authorization
Parameters
Request
curl -X POST 'https://api.norbelys.com/v1/webhook_endpoints/whe_0190f8a2b4c87a10b6d2e4f6a8c0e2f4/rotate_secret' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Idempotency-Key: string'
Response
{
  "created_at": "2019-08-24T14:15:22Z",
  "disabled_reason": "string",
  "enabled": true,
  "event_types": [
    "string"
  ],
  "failing_since": "2019-08-24T14:15:22Z",
  "id": "whe_0190f8a2b4c87a10b6d2e4f6a8c0e2f4",
  "secret": "string",
  "updated_at": "2019-08-24T14:15:22Z",
  "url": "string",
  "version": 0
}