Docs
Api referenceWebhooks

Rotate a webhook endpoint's secret

POST
/v1/webhooks/{id}/rotate

Issues a new secret, returned once. For 24 hours every delivery is signed with both the new and the old secret — two v1= values in fxapis-signature — so you can deploy the new one without missing an event.

Authorization

apiKey
AuthorizationBearer <token>

Authorization: Bearer fx_live_<id>_<secret>.

A key is shown once, at creation. We cannot show it again or recover it for you. Keys carry a label (live or test) in the key itself, so each configuration is easy to tell apart. Both reach real brokers: test with a broker demo account.

Scopes are per key. A key without accounts:write can read accounts and nothing else.

In: header

Path Parameters

id*string
Formatuuid

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/v1/webhooks/497f6eca-6276-4993-bfeb-53cbbbba6f08/rotate"
{  "data": {    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",    "url": "https://example.com/fxapis/webhooks",    "description": "Copier",    "events": [      "order.filled"    ],    "enabled": true,    "disabledAt": null,    "disabledReason": "20 deliveries in a row failed",    "consecutiveFailures": 0,    "secretHint": "whsec_…Qx4w",    "previousSecretExpiresAt": null,    "createdAt": "2019-08-24T14:15:22Z",    "updatedAt": "2019-08-24T14:15:22Z",    "secret": "whsec_3q2-7ZkT0d8m1sQe9yVbW4nX6pLr5aHcUgJf0oKxQx4w"  }}