Rotate Endpoint Secret
const url = 'https://app.lionrapid.com/api/webhooks/endpoints/example/rotate';const options = {method: 'POST'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://app.lionrapid.com/api/webhooks/endpoints/example/rotateMint a new HMAC secret for a generic endpoint. The response carries it EXACTLY ONCE.
Mirrors POST /integration-keys/{key_uuid}/rotate — same shape, same PM gate, a full object
back rather than a bare string. It updates the row IN PLACE rather than minting a successor:
this secret signs our outbound requests, so only one value is ever in use, and a successor row
would orphan the delivery observations keyed on endpoint_uuid.
Errors: 400: Slack endpoint — the URL is the credential; revoke it in Slack instead 404: Endpoint not found 403: Access denied (requires project manager)
Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Responses
Section titled “Responses”Successful Response
An endpoint WITH its secret. Returned by CREATE and ROTATE only — never by listing.
secret is the HMAC key for a generic receiver’s signature check, and is empty for a Slack
endpoint, where the URL itself is the credential. The route is PM-gated.
object
Examplegenerated
{ "endpoint_uuid": "example", "url": "example", "format": "example", "events": [ "example" ], "namespaces": [ "example" ], "active": true, "created_at": 1, "last_delivery_channel": "example", "last_delivery_outcome": "example", "last_delivery_at": 1, "last_delivery_ok_at": 1, "consecutive_delivery_failures": 1, "secret": "example"}Validation Error
object
object
Examplegenerated
{ "detail": [ { "loc": [ "example" ], "msg": "example", "type": "example" } ]}