View as Markdown

Rotate the signing secret for a webhook subscription

POST /v1/webhooks/{subscriptionId}/rotate-secret
Base URL
https://api.isnotai.com

Authenticate with Authorization: Bearer aik_v1_... (preferred) or the x-api-key header. Keys are region-bound. Authentication

Available Regions 2 regions

Generates and returns a NEW signing secret, invalidating the old one immediately. The response is one of only two places the secret ever appears (the other is the 201 from POST /v1/webhooks). Each call rotates again, so a blind retry after a timeout can leave you holding a stale secret - fetch deliveries failing signature verification is the symptom. Rotate, store, then verify with POST /v1/webhooks/{subscriptionId}/test.

Path Parameters

subscriptionId
string Required

Subscription id.

Responses

Any authenticated route can also return 401 (missing or invalid key), 429 RATE_LIMITED (edge rate limit; Retry-After is an integer number of seconds), and 5xx errors, even where not listed below. See Error Handling and Rate Limits.

200 application/json

Payload of WebhookSubscriptionCreatedResponse

Show 1 response attribute Hide response attributes
data
object
Show 16 data attributes Hide data attributes
id
string
integrationId
string
url
string
eventType
string

Event type name (string). Requests accept the name case-insensitively; responses return the PascalCase form shown here. Integers never appear on the wire.

Values are BotDetected, SessionAnomaly, ThresholdExceeded, AlertTriggered, ReportReady, SessionCorrelated, WritingSessionScored.
name
string
enabled
boolean
threshold
any
createdAt
string(date-time)
updatedAt
string(date-time)
lastDeliveryAt
string(date-time)
lastDeliveryStatus
string

Outcome of the most recent delivery attempt (string). Null until the first delivery.

Values are Pending, Delivered, Failed, MaxRetriesExceeded, PermanentFailure, PoisonAborted, null.
disabledAt
string(date-time)
disabledReason
string
disabledFailureClass
string
disabledDeliveryId
string
secret
string

One-time signing secret for X-Webhook-Signature verification. Returned ONLY by POST /v1/webhooks and POST /v1/webhooks/{subscriptionId}/rotate-secret; no other response ever includes it. Store it immediately; if lost, rotate.

401 application/json

Payload of ErrorEnvelope

Show 1 response attribute Hide response attributes
error
object
Show 3 error attributes Hide error attributes
code
string Required
message
string Required
details
object Required

Always present and null unless the error carries field-level context (validation errors set details.field to the offending parameter name).

404 application/json

Payload of ErrorEnvelope

Show 1 response attribute Hide response attributes
error
object
Show 3 error attributes Hide error attributes
code
string Required
message
string Required
details
object Required

Always present and null unless the error carries field-level context (validation errors set details.field to the offending parameter name).

POST /v1/webhooks/{subscriptionId}/rotate-secret
curl --request POST \
  --url https://api.isnotai.com/v1/webhooks/your-subscriptionId/rotate-secret \
  --header 'Authorization: Bearer aik_v1_YOUR_API_KEY'
import requests

url = "https://api.isnotai.com/v1/webhooks/your-subscriptionId/rotate-secret"

headers = {"Authorization": "Bearer aik_v1_YOUR_API_KEY"}

response = requests.post(url, headers=headers)

print(response.json())
const fetch = require('node-fetch');

const url = 'https://api.isnotai.com/v1/webhooks/your-subscriptionId/rotate-secret';
const options = {method: 'POST', headers: {Authorization: 'Bearer aik_v1_YOUR_API_KEY'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
using System.Net.Http.Headers;
var client = new HttpClient();
var request = new HttpRequestMessage
{
    Method = HttpMethod.Post,
    RequestUri = new Uri("https://api.isnotai.com/v1/webhooks/your-subscriptionId/rotate-secret"),
    Headers =
    {
        { "Authorization", "Bearer aik_v1_YOUR_API_KEY" },
    },
};
using (var response = await client.SendAsync(request))
{
    response.EnsureSuccessStatusCode();
    var body = await response.Content.ReadAsStringAsync();
    Console.WriteLine(body);
}

Try it

Collapse

Sent to the API as Authorization: Bearer aik_v1_.... Held only in this tab's input element; re-enter on each browser tab. The docs site never receives or stores it.

Path parameters

Subscription id.

200 Response examples
{
  "data": {
    "id": "example-id-123",
    "integrationId": "string",
    "url": "https://example.com",
    "eventType": "BotDetected",
    "name": "string",
    "enabled": false,
    "threshold": null,
    "createdAt": "2024-01-01T00:00:00Z",
    "updatedAt": "2024-01-01T00:00:00Z",
    "lastDeliveryAt": "2024-01-01T00:00:00Z",
    "lastDeliveryStatus": "Pending",
    "disabledAt": "2024-01-01T00:00:00Z",
    "disabledReason": "string",
    "disabledFailureClass": "string",
    "disabledDeliveryId": "string",
    "secret": "string"
  }
}
401 Response examples
{
  "error": {
    "code": "string",
    "message": "string",
    "details": {}
  }
}
404 Response examples
{
  "error": {
    "code": "string",
    "message": "string",
    "details": {}
  }
}