Generates a new signing secret for one webhook and returns the new plaintext value once. Store the returned secret immediately, because later reads only keep the encrypted version. Access requires an active organization administrator session or an organization API key with the `webhooks:write` scope. API-key calls also require the automation API module. Data is isolated to the authenticated organization; identifiers from another organization or site are not disclosed.
/api/webhooks/{id}/rotate-secretOrganization API key supplied as Authorization: Bearer convor_sk_....
In: header
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
{
"id": "11111111-1111-4111-8111-111111111111",
"secret": "generated-signing-secret-returned-once"
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication is required.",
"correlationId": "req_01K0MANAGEMENT401"
}
}{
"error": {
"code": "INTEGRATION_MODULE_REQUIRED",
"message": "The automation API module is required.",
"details": {
"module": "automation_api",
"feature": "public_api"
},
"correlationId": "req_01K0MANAGEMENT402"
}
}{
"error": {
"code": "FORBIDDEN",
"message": "The caller lacks the required role or API-key scope.",
"correlationId": "req_01K0MANAGEMENT403"
}
}{
"error": {
"code": "NOT_FOUND",
"message": "The requested resource was not found.",
"correlationId": "req_01K0MANAGEMENT404"
}
}{
"error": {
"code": "CONFLICT",
"message": "The requested change conflicts with current resource state.",
"correlationId": "req_01K0MANAGEMENT409"
}
}{
"error": {
"code": "VALIDATION_ERROR",
"message": "The request payload is invalid.",
"details": {
"field": "name"
},
"correlationId": "req_01K0MANAGEMENT422"
}
}{
"error": {
"code": "RATE_LIMITED",
"message": "Too many requests.",
"correlationId": "req_01K0MANAGEMENT429"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}curl --request POST \
'https://api.convor.io/api/webhooks/11111111-1111-4111-8111-111111111111/rotate-secret' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer convor_sk_...'const response = await fetch("https://api.convor.io/api/webhooks/11111111-1111-4111-8111-111111111111/rotate-secret", {
method: "POST",
headers: {
"Accept": "application/json",
"Authorization": "Bearer convor_sk_..."
},
});
const contentType = response.headers.get("content-type") ?? "";
const data = response.status === 204
? null
: contentType.includes("json")
? await response.json()
: contentType.startsWith("text/")
? await response.text()
: await response.blob();
if (!response.ok) {
const message = typeof data === "object" && data !== null
&& "error" in data && typeof data.error === "object"
&& data.error !== null && "message" in data.error
? String(data.error.message)
: "Convor API request failed (" + response.status + ")";
throw new Error(message);
}
console.log(data);Was this page helpful?
Retry a failed webhook delivery
Queues a new delivery attempt for a previously failed webhook delivery. Only deliveries in the failed state can be retried. Access requires an active organization administrator session or an organization API key with the `webhooks:write` scope. API-key calls also require the automation API module. Data is isolated to the authenticated organization; identifiers from another organization or site are not disclosed.
Send test payload to a webhook
Sends a test event to the webhook URL and reports delivery status. Use this to verify endpoint connectivity and inspect the remote response. When `event` is omitted it defaults to `conversation.created`, and when `payload` is omitted the test payload is an empty object. Access requires an active organization administrator session or an organization API key with the `webhooks:write` scope. API-key calls also require the automation API module. Data is isolated to the authenticated organization; identifiers from another organization or site are not disclosed.