curl --request POST \
--url https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"uuid": "<string>",
"url": "<string>",
"event_types": [
"<string>"
],
"status": "active",
"version": 123,
"description": "<string>",
"secret_hint": "<string>",
"created_at": "<string>",
"updated_at": "<string>",
"secret": "<string>"
}Rotate an event subscription's signing secret
Issues a new signing secret and returns it ONCE — the plaintext is never stored or returned again (Idempotency-Key replays return the same subscription without it). The previous secret stays valid for 24 hours so in-flight receivers keep verifying; a second rotation inside that window ends the first overlap immediately (at most two live secrets, no way to extend).
curl --request POST \
--url https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.journeybee.io/v1/event-subscriptions/{uuid}/rotate-secret")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"uuid": "<string>",
"url": "<string>",
"event_types": [
"<string>"
],
"status": "active",
"version": 123,
"description": "<string>",
"secret_hint": "<string>",
"created_at": "<string>",
"updated_at": "<string>",
"secret": "<string>"
}Authorizations
API key authentication. Use "Bearer <api_key>" or "Api-Key <api_key>".
Path Parameters
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Response
Default Response
HTTPS endpoint the events are POSTed to. Checked for SSRF at write time; delivery re-checks at send time.
2048Event types to subscribe to. Each entry is an exact v2 event type (e.g. lead.status_changed) or a trailing wildcard segment naming an object (e.g. lead.* for every lead type). See GET /v1/event-types for the catalogue.
paused stops delivery without deleting the subscription.
active, paused Envelope schema version delivered to this endpoint. Always 2 from /v1; immutable.
500Last four characters of the signing secret, for identification only. The full secret is returned once, in the POST response.
The signing secret for this subscription's deliveries. Returned only on the first response — an Idempotency-Key replay returns the same subscription with secret omitted. Store it now; it is never returned again.