Rotate a webhook signing secret
Activates a fresh signing-secret version for later deliveries while preserving retry authority for pinned older versions.
Authorizations
Per-request RFC 9449 DPoP proof signed with ES256. Protected requests use Authorization: DPoP your_access_token_here. Create a new proof for the exact method and normalized target URI, and include the server nonce when challenged.
OAuth 2.0 with RFC 9700 security practices. Discover exact environment endpoints from /.well-known/openid-configuration and /.well-known/oauth-authorization-server, and discover the resource from /.well-known/oauth-protected-resource. Authorization-code clients use PKCE S256, the exact environment resource, nonce with openid, and DPoP binding. Confidential clients also require PAR and private_key_jwt. Access and refresh tokens are sender-constrained with DPoP. purchases:execute is unavailable and omitted from this scope registry.
Headers
Optional caller request identifier. Unsafe values are replaced with a generated UUID.
^[A-Za-z0-9._~-]{8,128}$A new 256-bit random value encoded as 43 unpadded base64url characters. Reuse it only for the same request intent.
^[A-Za-z0-9_-]{43}$Path Parameters
API-owned webhook-subscription identifier.
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Response
The new signing secret, including exact equal replay.
A newly rotated signing secret, or the same exact idempotency replay.
Identifier of the new signing-secret version.
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Base64url-encoded 256-bit signing secret disclosed initially and on exact idempotency replay.
^[A-Za-z0-9_-]{43}$