BixelDocs
API reference

Rotate an endpoint's signing secret

POST
/v1/watch/endpoints/{id}/rotate

Mint a new whsec_ signing secret, returned ONCE in this response. The previous secret keeps verifying for a 24h grace window and deliveries carry both signatures meanwhile (space-delimited webhook-signature header), so consumers rotate without dropping an event. Costs 0 credits.

Authorization

AuthorizationBearer <token>

bx_-prefixed API key. Free keys: https://bixel.com/account/

In: header

Path Parameters

id*string

Response Body

application/json

application/problem+json

application/problem+json

curl -X POST "https://example.com/v1/watch/endpoints/string/rotate"
{  "data": {    "endpoint": {      "id": "string",      "url": "string",      "format": "json",      "status": "active",      "disabled_reason": "string",      "failing_since": "2019-08-24T14:15:22Z",      "secret_previous_expires_at": "2019-08-24T14:15:22Z",      "created_at": "2019-08-24T14:15:22Z"    },    "secret": "string"  },  "meta": {    "generated_at": "2019-08-24T14:15:22Z",    "count": 0,    "total": 0,    "next_cursor": "string",    "notice": "string",    "window": {      "served_from": "string",      "earliest_event_at": "string",      "events_beyond_window": true    }  }}
{  "type": "http://example.com",  "title": "string",  "status": 0,  "code": "company_not_found",  "detail": "string",  "hint": "string",  "docs_url": "http://example.com"}
{  "type": "http://example.com",  "title": "string",  "status": 0,  "code": "company_not_found",  "detail": "string",  "hint": "string",  "docs_url": "http://example.com"}