Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview

Rotate a subscription signing secret

Replace the signing secret and return the new plaintext value exactly once.

POST/api/v2/events/subscriptions/{subscriptionId}/rotate-secret
Authorization
AuthorizationBearer token (Anlyon API key) · headerrequired

Workspace API key sent as Authorization: Bearer <key>.

or
better-auth.session_tokenAPI key · cookierequired

Browser session used by dashboard-only operations.

Path parameters
subscriptionIdstringrequired

Public event subscription identifier.

matches ^sub_
Header parameters
X-Request-Idstring

Optional caller correlation ID. Unsafe or oversized values are replaced.

max length 128
Idempotency-Keystring

Stable retry key for a mutation. The key is claimed atomically before the handler runs, so concurrent retries execute the side effect at most once. Replaying the key for the same request (same method, path, workspace and JSON body) returns the original response with an X-Idempotent-Replay: true header. Reusing the key for a different request returns 409 with error code idempotency_key_reuse. A duplicate arriving while the first is still in flight waits and then replays; if the first does not finish in time the duplicate gets 409 idempotency_request_in_progress. Keys are retained for 24 hours. Only successful (2xx) responses are stored; a failed request frees the key so it can be retried.

min length 1 · max length 255
Responses
200

Newly rotated plaintext signing secret returned exactly once.

successbooleanrequired
Allowed:true
dataobjectrequired
Show properties
idstringrequired
matches ^sub_
secretstringrequired

Newly rotated plaintext signing secret. This value is returned exactly once.

401

Unauthorized - Invalid or missing API key

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
403

Authenticated credential lacks the required scope or workspace access.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
404

Not Found - Resource does not exist

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
429

Too Many Requests - Rate limit exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
Try it
Server
Authorization
Parameters
Request
curl -X POST 'https://api.anlyon.com/api/v2/events/subscriptions/string/rotate-secret' \
  -H 'Authorization: Bearer YOUR_TOKEN'
Response
{
  "success": true,
  "data": {
    "id": "string",
    "secret": "string"
  }
}