Rotate Signing Secret
Generate a new signing secret for a generic webhook and return it once.
Signs an unsigned webhook, or replaces the secret of a signed one: from
this call on, requests signed with any previous secret, or not signed, are
refused. The secret is in signing_secret of this response only.
Raises:
HTTPException: 404 if the trigger does not exist; 400 if it is not a
generic webhook (other channels are signed with their provider’s
secret); 409 if its secret is set inline in validation_rules or
webhook_config, which this call cannot replace.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Slug of the workspace the request acts in
120^[a-z0-9]+(?:-[a-z0-9]+)*$Response
Successful Response
Response model for trigger data.
Signing scheme of a generic webhook; null for other types.
Generated signing secret of a generic webhook. Returned only by the create and rotate calls that generated it; never readable afterwards.
What protects the public webhook URL. 'signed': requests without a valid signature or token are refused. 'unsigned': this trigger has no secret, so any request starts the agent. 'unsupported': the platform does not verify this provider's requests. Null for non-webhook triggers, or when the stored secret could not be read.
signed, unsigned, unsupported