curl --request POST \
--url https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret"
headers = {"X-API-Key": "<api-key>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"circuit_broken_until": "2026-01-15T10:40:00Z",
"created_at": "2026-01-15T10:30:00Z",
"description": "Production webhook receiver",
"enabled_events": [
"balance.credited",
"balance.debited"
],
"id": "550e8400-e29b-41d4-a716-446655440000",
"metadata": "<unknown>",
"rate_limited_until": "2026-01-15T10:35:00Z",
"secret": "whsec_a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2",
"status": "ACTIVE",
"updated_at": "2026-01-15T10:30:00Z",
"url": "https://example.com/webhooks"
}{
"code": "bad_request",
"details": {
"expected": "<string>",
"field": "<string>",
"fields": [
{
"expected": "<unknown>",
"field": "<string>",
"message": "This field is required",
"reason": "required",
"received": "<string>"
}
],
"reason": "invalid",
"received": "<string>"
},
"message": "Invalid request parameters"
}{
"code": "unauthorized",
"details": {
"expected": "<string>",
"field": "<string>",
"fields": [
{
"expected": "<unknown>",
"field": "<string>",
"message": "This field is required",
"reason": "required",
"received": "<string>"
}
],
"reason": "invalid",
"received": "<string>"
},
"message": "Missing or invalid credentials"
}{
"code": "forbidden",
"details": {
"expected": "<string>",
"field": "<string>",
"fields": [
{
"expected": "<unknown>",
"field": "<string>",
"message": "This field is required",
"reason": "required",
"received": "<string>"
}
],
"reason": "invalid",
"received": "<string>"
},
"message": "Insufficient permissions for this action"
}{
"code": "not_found",
"details": {
"expected": "<string>",
"field": "<string>",
"fields": [
{
"expected": "<unknown>",
"field": "<string>",
"message": "This field is required",
"reason": "required",
"received": "<string>"
}
],
"reason": "invalid",
"received": "<string>"
},
"message": "Resource not found"
}{
"code": "internal_error",
"message": "An internal error occurred"
}Rotate endpoint secret
Generate a new signing secret. The old secret is immediately invalidated.
curl --request POST \
--url https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret"
headers = {"X-API-Key": "<api-key>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.scrip.dev/v1/webhook-endpoints/{id}/rotate-secret")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"circuit_broken_until": "2026-01-15T10:40:00Z",
"created_at": "2026-01-15T10:30:00Z",
"description": "Production webhook receiver",
"enabled_events": [
"balance.credited",
"balance.debited"
],
"id": "550e8400-e29b-41d4-a716-446655440000",
"metadata": "<unknown>",
"rate_limited_until": "2026-01-15T10:35:00Z",
"secret": "whsec_a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2",
"status": "ACTIVE",
"updated_at": "2026-01-15T10:30:00Z",
"url": "https://example.com/webhooks"
}{
"code": "bad_request",
"details": {
"expected": "<string>",
"field": "<string>",
"fields": [
{
"expected": "<unknown>",
"field": "<string>",
"message": "This field is required",
"reason": "required",
"received": "<string>"
}
],
"reason": "invalid",
"received": "<string>"
},
"message": "Invalid request parameters"
}{
"code": "unauthorized",
"details": {
"expected": "<string>",
"field": "<string>",
"fields": [
{
"expected": "<unknown>",
"field": "<string>",
"message": "This field is required",
"reason": "required",
"received": "<string>"
}
],
"reason": "invalid",
"received": "<string>"
},
"message": "Missing or invalid credentials"
}{
"code": "forbidden",
"details": {
"expected": "<string>",
"field": "<string>",
"fields": [
{
"expected": "<unknown>",
"field": "<string>",
"message": "This field is required",
"reason": "required",
"received": "<string>"
}
],
"reason": "invalid",
"received": "<string>"
},
"message": "Insufficient permissions for this action"
}{
"code": "not_found",
"details": {
"expected": "<string>",
"field": "<string>",
"fields": [
{
"expected": "<unknown>",
"field": "<string>",
"message": "This field is required",
"reason": "required",
"received": "<string>"
}
],
"reason": "invalid",
"received": "<string>"
},
"message": "Resource not found"
}{
"code": "internal_error",
"message": "An internal error occurred"
}secret; store it and update your verification code before in-flight deliveries arrive.
Authorizations
API key passed in the X-API-Key header.
Path Parameters
Endpoint ID
Response
Endpoint with new secret
When set and in the future, the circuit breaker has paused deliveries to this endpoint until this time (sustained delivery failures)
"2026-01-15T10:40:00Z"
When the endpoint was created
"2026-01-15T10:30:00Z"
Human-readable label
"Production webhook receiver"
Subscribed event types
["balance.credited", "balance.debited"]
Endpoint ID
"550e8400-e29b-41d4-a716-446655440000"
Arbitrary metadata
When set and in the future, 429 rate-limit backoff has paused deliveries to this endpoint until this time
"2026-01-15T10:35:00Z"
Signing secret (only returned on create and rotate — store it immediately)
"whsec_a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2"
Lifecycle status: ACTIVE, DISABLED, or ARCHIVED
"ACTIVE"
When the endpoint was last modified
"2026-01-15T10:30:00Z"
Destination URL for deliveries
"https://example.com/webhooks"