Rotate the signing secret for a webhook subscription
https://api.isnotai.comAuthenticate with Authorization: Bearer aik_v1_... (preferred) or the x-api-key header. Keys are region-bound. Authentication
Generates and returns a NEW signing secret, invalidating the old one immediately. The response is one of only two places the secret ever appears (the other is the 201 from POST /v1/webhooks). Each call rotates again, so a blind retry after a timeout can leave you holding a stale secret - fetch deliveries failing signature verification is the symptom. Rotate, store, then verify with POST /v1/webhooks/{subscriptionId}/test.
Path Parameters
Subscription id.
Responses
Any authenticated route can also return 401 (missing or invalid key), 429 RATE_LIMITED (edge rate limit; Retry-After is an integer number of seconds), and 5xx errors, even where not listed below. See Error Handling and Rate Limits.
Payload of WebhookSubscriptionCreatedResponse
Payload of ErrorEnvelope
Payload of ErrorEnvelope
curl --request POST \
--url https://api.isnotai.com/v1/webhooks/your-subscriptionId/rotate-secret \
--header 'Authorization: Bearer aik_v1_YOUR_API_KEY'
import requests
url = "https://api.isnotai.com/v1/webhooks/your-subscriptionId/rotate-secret"
headers = {"Authorization": "Bearer aik_v1_YOUR_API_KEY"}
response = requests.post(url, headers=headers)
print(response.json())
const fetch = require('node-fetch');
const url = 'https://api.isnotai.com/v1/webhooks/your-subscriptionId/rotate-secret';
const options = {method: 'POST', headers: {Authorization: 'Bearer aik_v1_YOUR_API_KEY'}};
try {
const response = await fetch(url, options);
const data = await response.json();
console.log(data);
} catch (error) {
console.error(error);
}
using System.Net.Http.Headers;
var client = new HttpClient();
var request = new HttpRequestMessage
{
Method = HttpMethod.Post,
RequestUri = new Uri("https://api.isnotai.com/v1/webhooks/your-subscriptionId/rotate-secret"),
Headers =
{
{ "Authorization", "Bearer aik_v1_YOUR_API_KEY" },
},
};
using (var response = await client.SendAsync(request))
{
response.EnsureSuccessStatusCode();
var body = await response.Content.ReadAsStringAsync();
Console.WriteLine(body);
}
Sent to the API as Authorization: Bearer aik_v1_.... Held only in this tab's input element; re-enter on each browser tab. The docs site never receives or stores it.
{
"data": {
"id": "example-id-123",
"integrationId": "string",
"url": "https://example.com",
"eventType": "BotDetected",
"name": "string",
"enabled": false,
"threshold": null,
"createdAt": "2024-01-01T00:00:00Z",
"updatedAt": "2024-01-01T00:00:00Z",
"lastDeliveryAt": "2024-01-01T00:00:00Z",
"lastDeliveryStatus": "Pending",
"disabledAt": "2024-01-01T00:00:00Z",
"disabledReason": "string",
"disabledFailureClass": "string",
"disabledDeliveryId": "string",
"secret": "string"
}
}
{
"error": {
"code": "string",
"message": "string",
"details": {}
}
}
{
"error": {
"code": "string",
"message": "string",
"details": {}
}
}