Skip to content
agentsub
Esc
↑↓navigate↵open⌘Jpreview

Rotate webhook HMAC secret; secret shown once

POST/v1/merchants/{id}/webhook/rotate
Authorization
AuthorizationBearer token (JWT) · headerrequired

Clerk human owner session JWT; iss must equal the configured Clerk issuer and the identity must be a human (not agent) owner with a verified email.

or
AuthorizationOAuth2 access token · headerrequired
Scopes:agentsub:owner
Path parameters
idstringrequired
Header parameters
Idempotency-Keystringrequired

Required only where this parameter is listed. Same payload/key recovers prior operation; secret replays omit plaintext.

matches ^[A-Za-z0-9._:-]{1,200}$
Responses
200

Successful response

configurationWebhookConfiguration
Show properties
configuredboolean
enabledboolean
queueConfiguredboolean
merchantIdstring
urlstring<uri>
createdAtinteger
updatedAtinteger
webhookSecretstring
noticestring
401

unauthorized problem; live 401s advertise WWW-Authenticate: Bearer resource_metadata=...

typestringrequired
titlestringrequired
statusintegerrequired
codestringrequired
403

Identity, ownership, scope or policy denied (human_required, owner_claim_required, scope_required, FROZEN, CAP_EXCEEDED, SCOPE_FORBIDDEN)

typestringrequired
titlestringrequired
statusintegerrequired
codestringrequired
503

Runtime or provider configuration unavailable (runtime_configuration_required, signing_configuration_required, runtime_unavailable, workspace_unavailable, provider_configuration_required)

typestringrequired
titlestringrequired
statusintegerrequired
codestringrequired
Request
curl -X POST 'https://api.agentsub.dev/v1/merchants/string/webhook/rotate' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Idempotency-Key: string' \
  -H 'Accept: application/json'
Response
{
  "configuration": {
    "configured": true,
    "enabled": true,
    "queueConfigured": true,
    "merchantId": "string",
    "url": "http://example.com",
    "createdAt": 0,
    "updatedAt": 0
  },
  "webhookSecret": "string",
  "notice": "string"
}