Rotate a webhook endpoint's signing secret
using System.Net.Http.Headers;var client = new HttpClient();var request = new HttpRequestMessage{ Method = HttpMethod.Post, RequestUri = new Uri("https://api.roundrobinbot.eu/v1/webhooks/example/rotate"), Headers = { { "If-Match", "example" }, { "Authorization", "Bearer <token>" }, },};using (var response = await client.SendAsync(request)){ response.EnsureSuccessStatusCode(); var body = await response.Content.ReadAsStringAsync(); Console.WriteLine(body);}package main
import ( "fmt" "net/http" "io")
func main() {
url := "https://api.roundrobinbot.eu/v1/webhooks/example/rotate"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("If-Match", "example") req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close() body, _ := io.ReadAll(res.Body)
fmt.Println(res) fmt.Println(string(body))
}OkHttpClient client = new OkHttpClient();
Request request = new Request.Builder() .url("https://api.roundrobinbot.eu/v1/webhooks/example/rotate") .post(null) .addHeader("If-Match", "example") .addHeader("Authorization", "Bearer <token>") .build();
Response response = client.newCall(request).execute();import axios from 'axios';
const options = { method: 'POST', url: 'https://api.roundrobinbot.eu/v1/webhooks/example/rotate', headers: {'If-Match': 'example', Authorization: 'Bearer <token>'}};
try { const { data } = await axios.request(options); console.log(data);} catch (error) { console.error(error);}const url = 'https://api.roundrobinbot.eu/v1/webhooks/example/rotate';const options = { method: 'POST', headers: {'If-Match': 'example', Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.roundrobinbot.eu/v1/webhooks/example/rotate \ --header 'Authorization: Bearer <token>' \ --header 'If-Match: example'Issues a new signing secret and returns it once. The endpoint keeps its id, its URL, its subscriptions, its state and its delivery history. The outgoing secret keeps signing until previousSecretExpiresAt, and until then both signatures travel in one Round-Robin-Signature header, so a receiver can accept either and cut over without an outage.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Header Parameters
Section titled “Header Parameters”The ETag from your last read of this resource, sent back exactly as you received it, quotes included. The write happens only if nothing changed in between: a stale validator is answered 412 and nothing is written. Send * to write against whatever is current on purpose. Omitting the header is 428, never an unconditional write. https://docs.roundrobinbot.eu/api/conventions/#conditional-writes
Responses
Section titled “Responses”OK
The result of a secret rotation: the same endpoint, a new secret, and the cut-over deadline.
object
A registered destination: where Round Robin posts this workspace’s events, what it is subscribed to, and whether we are still calling it. Never the signing secret.
object
What the receiving system is called. Shown in the dashboard, never used for lookup.
Where we post. Always https.
What this endpoint receives: duty.changed, nobody.on_call, rotation.created, rotation.updated, rotation.deleted.
enabled or disabled. There is no revoked state: delete the endpoint instead.
Why we stopped calling: manual, delivery_failures or plan_downgrade. Absent while the endpoint is enabled.
Which secret is signing now, so your logs and ours name the same one.
The outgoing secret during a rotation’s grace window, absent at every other time.
When the outgoing secret stops signing. Until then both signatures travel in one header, so a receiver can cut over without an outage.
When the endpoint was registered.
The new secret. Returned once, like the first one.
When the outgoing secret stops signing, or null on an endpoint that had none to demote.
Examplegenerated
{ "endpoint": { "id": "example", "name": "example", "url": "example", "eventTypes": [ "example" ], "state": "example", "disabledReason": "example", "currentSecretId": "example", "currentSecretCreatedAt": "2026-04-15T12:00:00Z", "previousSecretId": "example", "previousSecretExpiresAt": "2026-04-15T12:00:00Z", "createdAt": "2026-04-15T12:00:00Z", "updatedAt": "2026-04-15T12:00:00Z" }, "signingSecret": "example", "previousSecretExpiresAt": "2026-04-15T12:00:00Z"}Bad Request
object
Examplegenerated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "instance": "example"}Unauthorized
object
Examplegenerated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "instance": "example"}Payment Required
object
Examplegenerated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "instance": "example"}Forbidden
object
Examplegenerated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "instance": "example"}Not Found
object
Examplegenerated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "instance": "example"}Conflict
object
Examplegenerated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "instance": "example"}Precondition Failed
object
Examplegenerated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "instance": "example"}Precondition Required
object
Examplegenerated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "instance": "example"}