Set, change or remove the key's webhook

PATCH/o/{org}/api-keys/{key}
View .md

Points the runFinished webhook of every run this key starts at a public https URL, or clears it with null. The signing secret (webhook_secret, whsec_…) is returned once, when the key first gets a URL and again on rotate_secret: true; changing the URL keeps it. Only the key's creator may call this.

Authenticate with a signed-in session token (an API key cannot call this route).

Path parameters

orgstringrequired

The org's slug or id. A caller with no role in the org gets 404.

keystringrequired

The key's id (key_…), not its secret.

Request body

webhook_urlstring | nulloptional
Format uriat most 2048 characters
rotate_secretbooleanoptional
Default false

Responses

200The key; webhook_secret only when a secret was minted.
idstringrequired

key_…; use it in the key routes.

namestringrequired
prefixstringrequired

The secret's first characters, to tell keys apart.

scopesarray of stringrequired
max_concurrentintegerrequired
webhook_urlstring | nullrequired
expires_atstring | nullrequired
Format date-time
created_byobjectrequired
2 fields
idstringrequired
emailstring | nullrequired
last_used_atstring | nullrequired
Format date-time
created_atstringrequired
Format date-time
secretstringoptional

The key's secret. Only in the create and rotate responses; never shown again.

webhook_secretstringoptional

The webhook signing secret. Only in the update response that minted it.

400An unknown field, a URL that is not public https, or rotate_secret with no URL (VALIDATION_ERROR).
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional
401No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional
404No such resource for the caller, including one that exists in an org the caller cannot see.
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional