Skip to content

Rotate a webhook endpoint's signing secret

POST
/v1/webhooks/{webhookId}/rotate
curl --request POST \
--url https://api.roundrobinbot.eu/v1/webhooks/example/rotate \
--header 'Authorization: Bearer <token>' \
--header 'If-Match: example'

Issues a new signing secret and returns it once. The endpoint keeps its id, its URL, its subscriptions, its state and its delivery history. The outgoing secret keeps signing until previousSecretExpiresAt, and until then both signatures travel in one Round-Robin-Signature header, so a receiver can accept either and cut over without an outage.

webhookId
required
string
If-Match
required
string

The ETag from your last read of this resource, sent back exactly as you received it, quotes included. The write happens only if nothing changed in between: a stale validator is answered 412 and nothing is written. Send * to write against whatever is current on purpose. Omitting the header is 428, never an unconditional write. https://docs.roundrobinbot.eu/api/conventions/#conditional-writes

OK

Media typeapplication/json

The result of a secret rotation: the same endpoint, a new secret, and the cut-over deadline.

object
endpoint

A registered destination: where Round Robin posts this workspace’s events, what it is subscribed to, and whether we are still calling it. Never the signing secret.

object
id
string
name

What the receiving system is called. Shown in the dashboard, never used for lookup.

string
url

Where we post. Always https.

string
eventTypes

What this endpoint receives: duty.changed, nobody.on_call, rotation.created, rotation.updated, rotation.deleted.

Array<string>
state

enabled or disabled. There is no revoked state: delete the endpoint instead.

string
disabledReason

Why we stopped calling: manual, delivery_failures or plan_downgrade. Absent while the endpoint is enabled.

null | string
currentSecretId

Which secret is signing now, so your logs and ours name the same one.

null | string
currentSecretCreatedAt
null | string format: date-time
previousSecretId

The outgoing secret during a rotation’s grace window, absent at every other time.

null | string
previousSecretExpiresAt

When the outgoing secret stops signing. Until then both signatures travel in one header, so a receiver can cut over without an outage.

null | string format: date-time
createdAt

When the endpoint was registered.

string format: date-time
updatedAt
null | string format: date-time
signingSecret

The new secret. Returned once, like the first one.

string
previousSecretExpiresAt

When the outgoing secret stops signing, or null on an endpoint that had none to demote.

null | string format: date-time
Examplegenerated
{
"endpoint": {
"id": "example",
"name": "example",
"url": "example",
"eventTypes": [
"example"
],
"state": "example",
"disabledReason": "example",
"currentSecretId": "example",
"currentSecretCreatedAt": "2026-04-15T12:00:00Z",
"previousSecretId": "example",
"previousSecretExpiresAt": "2026-04-15T12:00:00Z",
"createdAt": "2026-04-15T12:00:00Z",
"updatedAt": "2026-04-15T12:00:00Z"
},
"signingSecret": "example",
"previousSecretExpiresAt": "2026-04-15T12:00:00Z"
}

Bad Request

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Unauthorized

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Payment Required

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Forbidden

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Not Found

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Conflict

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Precondition Failed

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

Precondition Required

Media typeapplication/json
object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string
Examplegenerated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}