Skip to main content
POST
Rotate a webhook signing secret

Authorizations

Authorization
string
header
required

API key passed as a Bearer token

Path Parameters

webhook_id
string
required

Response

Successful Response

Rotate response — same shape as create; carries the new raw secret once.

id
string
required
url
string
required
events
enum<string>[]
required

Webhook event types exposed to API clients.

Mirrors SynapseWebhookEventType enum in datalayer (camelCase) but rendered to clients as snake_case dotted strings (closer to Stripe convention and easier to grep in caller logs).

Available options:
scribe_session.created,
scribe_session.completed,
scribe_session.error,
scribe_session.updated,
scribe_session.cancelled,
scribe_session.deleted
isActive
boolean
required
signingSecret
string
required

Raw HMAC signing secret. Shown once at creation — store it now; it is never retrievable again. Use it to verify the X-Scribe-Api-Signature header.

name
string | null

Optional human-readable label, or null if unset.

event
enum<string> | null
deprecated

Deprecated: the first subscribed event (events[0]). Use events.

Available options:
scribe_session.created,
scribe_session.completed,
scribe_session.error,
scribe_session.updated,
scribe_session.cancelled,
scribe_session.deleted
signingSecretPrefix
string | null

Display hint for the signing secret (e.g. 'whsec_a1b2c3d4'). The raw secret is only returned at creation/rotation.

signingSecretVersion
integer | null
createdAt
string | null
updatedAt
string | null
deletedAt
string | null