curl --silent --show-error --fail-with-body --request POST \
--url 'https://api.computer.stateset.app/api/v1/webhooks/{endpoint_id}/rotate-secret' \
--header "X-API-Key: $STATESET_COMPUTER_USE_API_KEY"
{
"id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"url": "https://example.com/webhooks/stateset",
"events": [
"string"
],
"is_active": true,
"created_at": "2026-08-31T14:22:05Z",
"updated_at": "2026-08-31T14:22:05Z",
"secret": "YOUR_API_KEY"
}
Mint a new signing secret in place; preserves delivery history.
Issue a new signing secret for an existing webhook endpoint. Mirrors POST /keys//rotate: row identity (id, url, events, is_active, created_at) is…
POST
/
api
/
v1
/
webhooks
/
{endpoint_id}
/
rotate-secret
curl --silent --show-error --fail-with-body --request POST \
--url 'https://api.computer.stateset.app/api/v1/webhooks/{endpoint_id}/rotate-secret' \
--header "X-API-Key: $STATESET_COMPUTER_USE_API_KEY"
{
"id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"url": "https://example.com/webhooks/stateset",
"events": [
"string"
],
"is_active": true,
"created_at": "2026-08-31T14:22:05Z",
"updated_at": "2026-08-31T14:22:05Z",
"secret": "YOUR_API_KEY"
}
Confirm your deployment before running this request. This page describes an API contract;
a published reference does not establish hosted availability. Check the dated
host report and obtain your deployment URL and credentials.
Replace the example host if your provisioned service uses a different URL.
POST /keys/{id}/rotate: row identity (id, url, events,
is_active, created_at) is preserved; only the secret changes.
updated_at advances. The new plaintext secret is returned in
full exactly once — read it before the response goes out the
door, because subsequent reads omit it.
The old secret stops working the instant this commits. Tenants
should orchestrate the cutover the same way as API keys: deploy
the new secret to the receiver before calling this, OR tolerate
a brief window of failed-signature deliveries.
Delivery history (success / failure / retry rows) is unchanged —
rotation deliberately preserves it so audit trails survive.
Inactive endpoints 409 (parallel to API key rotate). Cross-tenant
ids 404. Same scope (admin) as the rest of the webhook surface.
Path parameters
string (uuid)
required
Request body
No request body.Response
WebhookEndpointWithSecret
string
required
string
required
string[]
required
boolean
required
string
required
string
required
string
required
HMAC-SHA256 signing secret. Compare incoming X-Webhook-Signature against
HMAC(secret, f'{t}.{body}').Status codes
| Code | Meaning |
|---|---|
200 | Successful Response |
422 | Validation Error |
Using this contract
Read the source OpenAPI document for declared schemas and alternatives. This page also includes documented corrections from the spec overlays. Example IDs and values are illustrative; replace them with records from your workspace.curl --silent --show-error --fail-with-body --request POST \
--url 'https://api.computer.stateset.app/api/v1/webhooks/{endpoint_id}/rotate-secret' \
--header "X-API-Key: $STATESET_COMPUTER_USE_API_KEY"
{
"id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"url": "https://example.com/webhooks/stateset",
"events": [
"string"
],
"is_active": true,
"created_at": "2026-08-31T14:22:05Z",
"updated_at": "2026-08-31T14:22:05Z",
"secret": "YOUR_API_KEY"
}
Last modified on September 21, 2026