Skip to main content
POST
Rotate webhook secret

Authorizations

Authorization
string
header
required

Company-bound Case Management API key — the standard credential for this API.

Headers

X-On-Behalf-Of-Company
string<uuid>

Required when a Partner key calls the Case Management API; rejected for direct Case keys. Contains the entitled paywise company UUID.

Idempotency-Key
string
required

Required client-supplied command key scoped to the selected Case company or Partner owner, method, operation and path. An exact retry replays the original response while it is retained, including after credential rotation or replacement. Current permissions are required.

Maximum string length: 255

Path Parameters

id
string<uuid>
required

UUID of the webhook subscription in this request.

Response

Create / rotate-secret response — surfaces secret_key exactly once.

auto_disabled
boolean
required
read-only

true when the endpoint was disabled automatically after reaching max_consecutive_failures; re-enable it with enabled: true once the destination is fixed.

consecutive_failures
integer
required
read-only

Consecutive deliveries that reached terminal failure. Individual retry attempts do not increment this counter; a successful delivery resets it.

contract_version
enum<string>
required

Payload/signature contract of this endpoint. Endpoints created via this API are always v2; v1 marks a legacy subscription that still receives v1 payloads and must be recreated to migrate.

  • v1 - Legacy v1
  • v2 - Version 2
Available options:
v1,
v2
created_at
string<date-time>
required
read-only

Time at which the webhook subscription was created.

id
string<uuid>
required
read-only

Stable identifier for this resource.

last_failure_at
string<date-time> | null
required
read-only

Time of the most recent terminal delivery failure since the last successful delivery; null after a successful delivery or when no failure has been recorded.

updated_at
string<date-time>
required
read-only

Time at which the webhook subscription was last updated.

url
string<uri>
required

Publicly reachable HTTPS URL for webhook notifications. Must be unique among this company’s v2 endpoints; duplicate checks normalize the scheme, host, and default port.

Maximum string length: 2048
description
string

Optional single-line label for this webhook.

Maximum string length: 255
enabled
boolean

Whether deliveries are attempted. Re-enabling an endpoint resets its consecutive failure counter.

events
enum<string>[]

Current public event subscriptions for this endpoint. ["*"] subscribes to all public events; otherwise the list contains the subscribed event types.

  • * - *
  • order.submitted - order.submitted
  • order.withdrawn - order.withdrawn
  • order.rejected - order.rejected
  • order.accepted - order.accepted
  • order.expired - order.expired
  • mandate.created - mandate.created
  • mandate.state.changed - mandate.state.changed
  • mandate.status_update.published - mandate.status_update.published
  • mandate.balance_updated - mandate.balance_updated
  • order.message.created - order.message.created
  • mandate.message.created - mandate.message.created
  • request_to_client.created - request_to_client.created
  • request_to_client.answered - request_to_client.answered
  • payment.reported - payment.reported
  • statement.published - statement.published
  • statement.cancelled - statement.cancelled
  • single_mandate_statement.published - single_mandate_statement.published
  • single_mandate_statement.cancelled - single_mandate_statement.cancelled
  • invoice.created - invoice.created
  • invoice.paid - invoice.paid
  • invoice.cancelled - invoice.cancelled
  • invoice.written_off - invoice.written_off
  • dunning.level_advanced - dunning.level_advanced
  • dunning.handed_to_collection - dunning.handed_to_collection
Available options:
*,
order.submitted,
order.withdrawn,
order.rejected,
order.accepted,
order.expired,
mandate.created,
mandate.state.changed,
mandate.status_update.published,
mandate.balance_updated,
order.message.created,
mandate.message.created,
request_to_client.created,
request_to_client.answered,
payment.reported,
statement.published,
statement.cancelled,
single_mandate_statement.published,
single_mandate_statement.cancelled,
invoice.created,
invoice.paid,
invoice.cancelled,
invoice.written_off,
dunning.level_advanced,
dunning.handed_to_collection
max_consecutive_failures
integer

Automatically disables the endpoint when this many consecutive deliveries reach terminal failure. Retry attempts within one delivery do not each count.

Required range: 1 <= x <= 1000
secret_key
string
read-only

Signing secret shown once on creation or rotation. Store it to verify webhook signatures; list, retrieve, and idempotent replay responses omit it.