Skip to main content
POST
cURL
Activate the secret you created with Prepare a staged webhook secret. Deliveries include signatures from both secrets for 1 hour, so your receiver can accept either while you finish deploying the new secret. Once every receiver accepts the new secret, call Retire a staged webhook secret to end the overlap early.

Parameters

Key response fields

What your receiver sees during the overlap

x-0xinsider-signature carries two v1=<hex> values separated by a comma: the new secret’s signature first, the previous secret’s second. Compute the HMAC-SHA256 of <timestamp>.<raw body> for each secret you hold, and accept the delivery when either candidate matches. Keep doing that until the overlap is over.

Example

Handle a 409 or a 422

What it does not do

  • Drop the previous secret straight away. It stays valid until you call Retire a staged webhook secret or overlap_expires_at passes.
  • Return the previous secret. It is only used to add the second signature during the overlap.
  • Send a verification challenge. status, url, and event_types are untouched, so the endpoint keeps delivering throughout.
  • Double-sign the verification challenge. Verify a webhook always signs with the current secret alone.

Authorizations

Authorization
string
header
required

Legacy default or named integration API key, or OAuth 2.1 access token, in the Authorization header as Bearer oxi_sk_live_... or Bearer oxi_at_.... Default keys retain full access; integration keys are limited to their approved read, webhooks, export and usage scopes and expire within 90 days. All credentials share the owner's account limits. Data calls require an active Pro subscription and return live data. A 401 carries WWW-Authenticate: Bearer resource_metadata="https://api.0xinsider.com/.well-known/oauth-protected-resource" (RFC 6750 section 3, RFC 9728).

Headers

Idempotency-Key
string

Optional safe-retry key. Reuse the same value only when retrying the exact same mutation request body; a different body returns 422 and an in-flight matching request returns 409.

Required string length: 1 - 255

Path Parameters

id
integer<int64>
required

Webhook endpoint id owned by the authenticated API key user.

Response

Webhook destination with the activated signing secret

object
string
required
Allowed value: "webhook"
data
object
required
meta
object
required