Add a webhook signing secret

Generate a signing secret for an unsigned webhook. Fails if a secret is already configured. Save the returned secret; it cannot be retrieved afterward.

Required permissions: notification_endpoint:update.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Path parameters

notification_endpoint_idstringRequired
The ID of the webhook endpoint.

Headers

X-Penny-As-Businessstring or nullOptional

Act on behalf of another business that has granted you access. Requires the business:act_as permission.

Response

Successful Response
signing_secretstring
New signing secret. Returned only by creation and rotation operations. Use the entire string, including its prefix, as the HMAC key.
algorithm"HMAC-SHA256"OptionalDefaults to HMAC-SHA256

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
422
Unprocessable Entity Error
429
Too Many Requests Error
500
Internal Server Error