Skip to main content
POST
cURL
After Activate a staged webhook secret, use this endpoint to stop signing deliveries with the previous secret. Future deliveries carry only the current secret’s signature. You can retire early once every receiver accepts the new secret, or let the overlap expire 1 hour after activation. Repeating the request returns the current state without another change.

Parameters

Key response fields

Example

Handle a 409 or a 422

Retiring when nothing is in overlap is not a conflict, so this route never answers webhook_secret_rotation_not_prepared or webhook_secret_rotation_overlap_active.

What it does not do

  • Change the current signing secret. To replace it, run the staged rotation again from Prepare a staged webhook secret, or swap it at once with Rotate a webhook secret.
  • Cancel a prepared secret. If you called prepare and never activated, secret_rotation.status still reads pending after this call.
  • Return either secret. Future deliveries are signed with the current secret only, and read endpoints never return it.
  • Resend deliveries or change the endpoint’s url, status, or event_types.

Authorizations

Authorization
string
header
required

Legacy default or named integration API key, or OAuth 2.1 access token, in the Authorization header as Bearer oxi_sk_live_... or Bearer oxi_at_.... Default keys retain full access; integration keys are limited to their approved read, webhooks, export and usage scopes and expire within 90 days. All credentials share the owner's account limits. Data calls require an active Pro subscription and return live data. A 401 carries WWW-Authenticate: Bearer resource_metadata="https://api.0xinsider.com/.well-known/oauth-protected-resource" (RFC 6750 section 3, RFC 9728).

Headers

Idempotency-Key
string

Optional safe-retry key. Reuse the same value only when retrying the exact same mutation request body; a different body returns 422 and an in-flight matching request returns 409.

Required string length: 1 - 255

Path Parameters

id
integer<int64>
required

Webhook endpoint id owned by the authenticated API key user.

Response

Webhook destination after the previous signing secret is retired

object
string
required
Allowed value: "webhook"
data
object
required
meta
object
required