Atomically replace the endpoint’s signing secret. The new plaintext secret is returned ONCE — same UX as create. Receivers that need a graceful rotation window should temporarily verify against both the old and the new secret; the verifier in lib/webhooks/signing.ts already supports multiple v1= values per signature header. Admin role or higher.
Documentation Index
Fetch the complete documentation index at: https://docs.autousers.ai/llms.txt
Use this file to discover all available pages before exploring further.
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Client-generated idempotency key (≤255 chars). Replays the cached response when the same (team, key) pair sees an identical request body within 24h; returns 409 idempotency_key_reused if the body differs. Recommended for every billable POST.
255Date-pinned API version (e.g. 2026-05-04). Omit to receive the latest stable version. Behaves like Stripe's Stripe-Version — pinning a version freezes payload shapes against breaking changes during the 12-month sunset window.
cuid of the resource
Secret rotated — new plaintext secret returned ONCE
Plaintext signing secret (whsec_*). Returned ONCE on create / rotate-secret and never again — persist immediately or call rotate-secret to mint a new one.
enabled, disabled