AlmondTill/G3N API

On this page

rotateWebhookSubscriptionSecret

mutation · in the family System and integration setup

What it does

Mint a fresh signing secret for a webhook — the old one stops working immediately.

Mint a FRESH signing secret for one webhook subscription: overwrites the credential-store row and returns the new secret ONCE, effective IMMEDIATELY (no dual-validity window — update your receiver first, then rotate); a doomed subscription refuses CONFLICT/IMMUTABLE. OWNER-gated ENGINE-side; OCC on the passed revision. Template class (hand-derived v71).

What happens

The new secret shows ONCE; update your receiver before you rotate.

Careful

OWNER-gated. No grace window — deliveries sign with the new secret from this moment.

Who may call it

Capability area: System and integration setup — Registers, connections and the settings your systems run on.

Arguments

NameTypeRequiredNotes
idID ID!yesThe id of the record.
revisionID ID!yesThe revision id you read on the record; the change is refused if an edit landed in the meantime.
reasonStringnoNo further notes.

Returns

WebhookSubscriptionSecretRotation WebhookSubscriptionSecretRotation! — The rotateWebhookSubscriptionSecret result — the fresh secret, returned ONCE; the old secret is dead from this instant (no dual-validity window — update your receiver FIRST).

Example request

mutation ExampleRotateWebhookSubscriptionSecret($id: ID!, $revision: ID!, $reason: String) {
  rotateWebhookSubscriptionSecret(id: $id, revision: $revision, reason: $reason) {
    secret
  }
}

Variables:

{
  "id": "01900000-0000-7000-8000-37386ae00000",
  "revision": "01900000-0000-7000-8000-b7960e180000",
  "reason": "Correcting a miscount."
}

Send it with the envelope naming the version: "extensions": {"at": {"version": {"name":"genesis","number":0}}}.

Example response

{
  "data": {
    "rotateWebhookSubscriptionSecret": {
      "secret": "<your key secret>"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}

Errors this call can answer

Used in