Mint a new webhook signing secret
Generate a new signing secret for webhook deliveries on the authenticated account. Every webhook this API sends is signed with this secret so your receiver can verify the payload actually came from us. Rotating takes effect immediately — deliveries in flight are signed with the old secret, so accept both for a short window when rotating a live receiver. The secret is returned **once, in this response**. Unmetered.
Authorization
BearerAuth Your API key, sent as Authorization: Bearer wm_.... Keys are wm_ followed by 40 hex characters. Create one with POST /register (free, no auth) or POST /keys.
In: header
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/webhook/rotate"{ "rotated_at": "2019-08-24T14:15:22Z", "webhook_signing_secret": "string"}Revoke an API key (stops working immediately)
Revoke a key on the authenticated account. The key stops authenticating immediately — there is no grace period, so revoke only after the replacement is deployed. Revocation is permanent and cannot be undone; mint a new key instead. The row remains listable with `revoked_at` set, so the audit trail survives. Unmetered.
Your request history (audit log)
Return the authenticated account's recent API requests — URL, endpoint, status, latency and which key made the call. Useful for reconciling a bill against actual usage, or finding which key is responsible for unexpected traffic. Paginate with `limit` (1-200, default 50) and `offset`, newest first. Unmetered — reading your own history never consumes quota.