POST
/webhook-endpoints/{id}/rotate-secretRotate a webhook signing secret
The new secret is returned only in this response and an exact idempotent replay.
Bearer Token
webhooks:manageRequest
curl --request POST \
'https://sandbox-api.padel-lab.crewio.co/v1/club/webhook-endpoints/resource_01JABC/rotate-secret' \
--header 'Authorization: Bearer $PADEL_LAB_TOKEN' \
--header 'Idempotency-Key: 018f-unique-request-key'Parameter
idpathIdrequiredIdempotency-KeyheaderstringrequiredUnique key retained for 24 hours on authenticated mutation endpoints. The installation-exchange binding is retained permanently with its consumed authorization code. Reuse with different request content returns IDEMPOTENCY_CONFLICT.
Responses
200Secret rotatedWebhookSecretRotationResponse400Malformed JSON or a syntactically valid request that violates a path, query, header or JSON-body constraint.ErrorResponse401Missing, invalid or expired tokenErrorResponse403Installation lacks the required scope or is inactiveErrorResponse404Resource is absent or outside the token-bound tenantErrorResponse409Version, idempotency, mapping, state or resource-limit conflictErrorResponse429Rate limit exceededErrorResponse500An unexpected runtime error occurred; retry only when the operation is safe or idempotent.ErrorResponse503A required authorization, tenant-safety or rate-limit dependency is unavailableErrorResponseResponse Schemas
WebhookSecretRotationResponseStatus 200
{
"type": "object",
"required": [
"data"
],
"properties": {
"data": {
"type": "object",
"additionalProperties": false,
"required": [
"id",
"signing_secret",
"signing_secret_version"
],
"properties": {
"id": {
"type": "string",
"minLength": 1,
"maxLength": 200,
"description": "Opaque stable identifier"
},
"signing_secret": {
"type": "string",
"readOnly": true
},
"signing_secret_version": {
"type": "integer",
"minimum": 2
}
}
}
}
}ErrorResponseStatus 400, 401, 403, 404, 409, 429, 500, 503
{
"type": "object",
"additionalProperties": false,
"required": [
"error"
],
"properties": {
"error": {
"type": "object",
"additionalProperties": false,
"required": [
"code",
"message",
"request_id"
],
"properties": {
"code": {
"type": "string",
"description": "Stable machine-readable code. Clients must tolerate unknown codes within the same HTTP class.",
"examples": [
"invalid_request",
"invalid_cursor",
"IDEMPOTENCY_KEY_REQUIRED",
"unsafe_webhook_url",
"authentication_required",
"invalid_token",
"insufficient_scope",
"installation_inactive",
"not_found",
"VERSION_CONFLICT",
"UNMAPPED_COURT",
"IDEMPOTENCY_CONFLICT",
"IDEMPOTENCY_IN_PROGRESS",
"endpoint_limit_reached",
"rate_limited",
"internal_error",
"idempotency_replay_failed",
"authorization_unavailable",
"rate_limit_unavailable"
]
},
"message": {
"type": "string"
},
"request_id": {
"type": "string"
},
"details": {}
}
}
}
}