Saltar al contenido principal
POST
Rota el secreto de firma

Autorizaciones

Authorization
string
header
requerido

Un JWT bearer emitido por plugin-auth (lib-auth). La identidad del tenant se resuelve a partir de los claims validados del token; la superficie /v1 nunca lee un tenant del cuerpo, del path ni de la query. Los llamadores de máquina obtienen un token vía el flujo client-credentials de plugin-auth. La superficie /admin autoriza contra un scope de operador y no lleva contexto de tenant.

Encabezados

X-Idempotency
string
requerido

A client-chosen unique key that makes this mutation at-most-once. A mutation sent without it is rejected before any write with 400 missing_idempotency_key. Reusing the same key with an identical request replays the original response byte-for-byte (with X-Idempotency-Replayed: true); reusing it with a different request body returns 409 idempotency_conflict. To re-drive a corrected request, mint a new key.

Parámetros de ruta

id
string<uuid>
requerido

The unique identifier of the subscription (UUIDv7).

Respuesta

Se generó un nuevo secreto de firma. signingSecret se muestra exactamente una vez — guárdalo al recibirlo.

signingSecret
string
requerido

The new one-time signing secret (write-only). Shown exactly once here.

Ejemplo:

"whsec_1a2b3c4d5e6f7081a2b3c4d5e6f70819"

overlapUntil
string<date-time>
requerido

The moment the previous secret stops being valid for verification (UTC, RFC 3339) — a 24-hour dual-sign overlap.

Ejemplo:

"2026-06-06T12:00:00Z"