TokenLab

Management

Rotate webhook signing secret

Requires a workspace Management Token (mt-...), created at Dashboard > API > Management Tokens. Send Authorization: Bearer mt-.... Inference API keys (sk-...) and webhook signing secrets (whsec_...) are not accepted. Only the token workspace is accessible. The full whsec_ signing secret is returned only on creation or rotation. Store it securely; GET/list never return it. Rotation takes effect immediately for new deliveries; already in-flight deliveries can still use the previous secret.

POSThttps://api.tokenlab.sh/v1/management/webhooks/{webhookId}/rotate-secret

Use a workspace Management Token (mt-...), not an inference API key (sk-...) or signing secret (whsec_...). Create one at Dashboard → API → Management Tokens and send Authorization: Bearer mt-.... Access is scoped to that workspace.

See Webhook management API guide for events, verification, retries and troubleshooting.

curl -X POST "https://example.com/v1/management/webhooks/string/rotate-secret"
{  "id": "string",  "object": "webhook_endpoint",  "url": "string",  "events": [    "task.completed"  ],  "is_active": true,  "description": "string",  "created_at": "2019-08-24T14:15:22Z",  "updated_at": "2019-08-24T14:15:22Z",  "last_delivered_at": "2019-08-24T14:15:22Z",  "failure_count": 0,  "secret": "string"}

Authorization

ManagementTokenAuth
AuthorizationBearer <token>

Management token authentication. Create or manage Management Tokens in Dashboard > API > Management Tokens.

In: header

Path Parameters

webhookId*string
Length1 <= length <= 128

Response

application/json

application/json

application/json

application/json

application/json

application/json