Skip to navigation

Rotate an event subscription's secret

View as Markdown

Authentication

AuthorizationBearer

Your Truvo API key, sent as a bearer token. The prefix selects sandbox (trv_sandbox_) or live (trv_live_).

Path parameters

idstringRequired

Headers

Truvo-VersionenumRequiredDefaults to 2026-09-26

The contract revision of this request, which every operation in this document requires. This document describes 2026-09-26. Served revisions: 2026-09-26. A missing header, or one that names no served revision exactly, answers invalid_version (400), and its field error lists the served revisions in allowed_values, newest first.

Allowed values:
Idempotency-KeystringRequired

A caller-chosen request key. A key replays for at least 24 hours. The same key with the same body replays the first answer; the same key with a different body is a conflict.

Response headers

Request-Idstringformat: "^req_[0-9a-f]{16}$"

The ID of this answer. An error body repeats it as request_id.

Truvo-Versionstringformat: "^[0-9]{4}-[0-9]{2}-[0-9]{2}$"

The contract revision of this answer: the revision that the request named in Truvo-Version. A 404, and a refusal sent before Truvo knows your revision (401, 413, a 429 for failed authentication, and a 400 invalid_version), name the current revision and take its shape.

RateLimit-LimitintegerOptional
The calls this window allows, for the limit you're closest to reaching. The window is one minute or one UTC day. A fixed window allows a burst of up to twice the limit across a window edge.
RateLimit-RemainingintegerOptional
The calls left in the current window.
RateLimit-ResetintegerOptional
Seconds until the current window ends and the count resets.

Response

Replace the signing secret. The answer carries the new secret once. The old secret stays valid for 24 hours.
idstringformat: "^sub_[a-z0-9]{8,64}$"
signing_secretstring or null>=1 character
previous_secret_expires_atdatetime

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
409
Conflict Error
413
Content Too Large Error
422
Unprocessable Entity Error
429
Too Many Requests Error
500
Internal Server Error
503
Service Unavailable Error