Rotate the signing secret
Mints a new whsec_ and returns it once. The old secret stops validating immediately. Requires webhooks:manage.
POST
/webhook-endpoints/{endpointId}/rotate-secretAuthorization
AuthorizationBearer token (tp_live_...) · headerrequiredA TipPage API key, created in Dashboard → Settings → Developer.
Path parameters
endpointIdstringrequiredWebhook endpoint id (`we_...`).
Responses
200The new secret - shown only here.
secretstring401Missing or invalid API key (`missing_api_key` / `invalid_api_key`).
errorstringrequiredHuman-readable message.
codestringMachine-readable code (e.g. `missing_scope`, `not_in_queue`).
403The key lacks the required scope (`missing_scope`).
errorstringrequiredHuman-readable message.
codestringMachine-readable code (e.g. `missing_scope`, `not_in_queue`).
required_scopestring404No such resource.
errorstringrequiredHuman-readable message.
codestringMachine-readable code (e.g. `missing_scope`, `not_in_queue`).
429Rate limit exceeded - check the `RateLimit-*` headers.
errorstringRequest
curl -X POST "https://api.tippage.com/v1/webhook-endpoints/string/rotate-secret" \
-H "Authorization: Bearer YOUR_TOKEN"const response = await fetch("https://api.tippage.com/v1/webhook-endpoints/string/rotate-secret", {
method: "POST",
headers: {
"Authorization": "Bearer YOUR_TOKEN"
}
});import requests
response = requests.post(
"https://api.tippage.com/v1/webhook-endpoints/string/rotate-secret",
headers={
"Authorization": "Bearer YOUR_TOKEN"
},
)Response
{
"secret": "whsec_1a2b3c..."
}{
"error": "string",
"code": "string"
}{
"error": "string",
"code": "string",
"required_scope": "string"
}{
"error": "string",
"code": "string"
}{
"error": "string"
}