Fac-360
Webhooks

Mint the next signing secret version

Creates the next secret version and switches signing to it immediately; there is no overlap window, so install the new secret before rotating. The new secret is returned exactly once. A replay of the same Idempotency-Key answers 200 with replay=true and no secret; if the value was lost, rotate again with a new key.

POST
/api/v2/webhooks/subscriptions/{id}/secret-rotations

Creates the next secret version and switches signing to it immediately; there is no overlap window, so install the new secret before rotating. The new secret is returned exactly once. A replay of the same Idempotency-Key answers 200 with replay=true and no secret; if the value was lost, rotate again with a new key.

Authorization

bearerAuth
AuthorizationBearer <token>

Tenant-bound, scoped and expiring Apifact credential. Migrated legacy credentials are accepted only on deprecated v1 writes and tenant-scoped v2 read, poll and download routes. Each operation names the single scope it requires in x-required-scope; the scope array of the security requirement itself is empty because OpenAPI 3.0 requires it to be for a non-oauth2 scheme.

In: header

Path Parameters

id*string
Formatuuid

Header Parameters

Idempotency-Key*string
Match^[!-~]+$
Length1 <= length <= 200

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v2/webhooks/subscriptions/497f6eca-6276-4993-bfeb-53cbbbba6f08/secret-rotations" \  -H "Idempotency-Key: b6a2f0e4-1c3d-4a5b-8e7f-9d0c1b2a3e4f" \  -H "Authorization: Bearer apf_v2_tu_credencial"
{  "schemaVersion": "2.0",  "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",  "subscriptionId": "d079718b-ff63-45dd-947b-4950c023750f",  "secretVersion": 2,  "secret": "string",  "replay": true}