Rotate webhook endpoint secret
Mint a new HMAC signing secret for the endpoint and return it in the
response secret field (shown exactly once). The previous secret stops
signing immediately, so accept both during your cutover window.
Authentication
Enter your API key with the Bearer prefix, e.g. ‘Bearer sk_…’.
Path parameters
Webhook endpoint id (prefixed whe_…).
Headers
Response headers
Response
The endpoint, including its new one-time signing secret.
Prefixed wire id (whe_<26 char Crockford base32>).
The events this endpoint receives: a list of catalog event names
(see WebhookEventType) or ["*"] for every event, current and
future.
Per-event payload shaping. Deliveries are lean by default:
data.object carries only the resource GET snapshot. List heavy
collections here to have them appended under the event’s data
alongside object, so receivers behind hard request-size caps stay
lean unless they opt in. Recognised keys (conversation events only):
messages (the full transcript) and evaluations. Empty = lean.
The dated payload shape this endpoint receives (YYYY-MM-DD), the
same versioning vocabulary the REST API uses. Every delivery is
rendered back to this version and carries it in the
Speechify-Version header and the payload’s top-level version
field. Defaults to your workspace’s current version at creation;
change it to opt into a newer shape.
The project whose events this endpoint receives (prefixed external id). Null means workspace-wide - it receives every project’s events. Endpoints have no Default project.
Optional human-readable label for the endpoint.
The HMAC-SHA256 signing secret (whsec_…) used to verify the
Speechify-Signature header. Returned ONLY when the endpoint is
created or its secret is rotated — it is never shown again.