Points the runFinished webhook of every run this key starts at a
public https URL, or clears it with null. The signing secret
(webhook_secret, whsec_…) is returned once, when the key first gets
a URL and again on rotate_secret: true; changing the URL keeps it.
Only the key's creator may call this.
Authenticate with a signed-in session token (an API key cannot call this route).
Path parameters
The org's slug or id. A caller with no role in the org gets 404.
The key's id (key_…), not its secret.
Request body
falseResponses
200The key; webhook_secret only when a secret was minted.
key_…; use it in the key routes.
The secret's first characters, to tell keys apart.
2 fields
The key's secret. Only in the create and rotate responses; never shown again.
The webhook signing secret. Only in the update response that minted it.
400An unknown field, a URL that is not public https, or rotate_secret with no URL (VALIDATION_ERROR).
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.
401No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.
404No such resource for the caller, including one that exists in an org the caller cannot see.
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.