Rotate webhook signing secret
Generates a new HMAC-SHA256 signing secret for the webhook, immediately invalidating the previous one. Update your receiver’s verification logic before calling this endpoint to avoid delivery failures.
Documentation Index
Fetch the complete documentation index at: https://docs.cyberun.cloud/llms.txt
Use this file to discover all available pages before exploring further.
Authorizations
User session JWT (Bearer ). Must be paired with the X-Team-ID
request header on team-scoped endpoints so the server knows which
team's resources to operate on.
Headers
UUID of the team to scope the request to. Used by dual-auth endpoints (runtime + scoped management):
- JWT callers MUST send it — a user may belong to multiple teams and the runtime cannot otherwise know which one to operate on. Missing header → 400.
- Credential callers (
sk-,dk-) can omit it because the team is derived from the credential row itself. Any value sent is ignored.
"019abc12-4567-7890-abcd-ef1234567891"
Path Parameters
UUID of the webhook.
"019abc12-0123-7890-abcd-ef1234567897"
Response
New signing secret
New webhook signing secret after rotation.
New HMAC-SHA256 signing secret (prefixed with whsec_). The previous
secret is immediately invalidated. Update your verification logic before
calling this endpoint.
"whsec_b2c3d4e5f6g7h8i9j0k1"
