This instance couldn't reach its API specification on the last attempt, so this page shows the copy fetched before that. Anything added or changed since then is missing here, and the reference updates itself as soon as the specification is readable again. Last fetched 2026-10-09 02:57 UTC.
The replacement secret becomes the destination's only signing secret, the outgoing one is
retired, and deliveries return to a single signature value immediately.
Signed in, you can send this request to your own sandbox merchant from the console
and read the answer.
Sign in to try it.
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a . See the Request body section below for its fields.
Parameters
Name
In
Type
Description
idrequired
path
string (uuid)
suppressNullsrequired
query
boolean
If true, omit properties with null values.
Request body
application/json, required
Field
Type
Description
This request body has no documented fields.
Responses
200OK
Body: WebhookSecretRotationStateDtoEach item has these fields.
Field
Type
Description
isRotatingrequired
boolean
Whether an overlap is open, so deliveries carry two signature values.
rotationStartedUtcrequired
string (date-time)
When the overlap began, UTC. Null when no rotation is in progress.nullable
This response has no documented body fields.
defaultThe request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponseEach item has these fields.
Field
Type
Description
errorrequired
RemoteServiceErrorInfo
This response has no documented body fields.
429The request was refused because a rate limit was exceeded, or because something a later retry can clear stopped it. A rate limit refusal carries an `application/problem+json` body: wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling. Any other refusal carries the standard error envelope as `application/json`, and its `error.code` names the cause.
Body: RemoteServiceErrorResponseEach item has these fields.
Field
Type
Description
errorrequired
RemoteServiceErrorInfo
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.