import requests
url = "https://api.paywise.de/v2/webhooks/{id}/rotate-secret/"
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Idempotency-Key': '<idempotency-key>', Authorization: 'Bearer <token>'}
};
fetch('https://api.paywise.de/v2/webhooks/{id}/rotate-secret/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));HttpResponse<String> response = Unirest.post("https://api.paywise.de/v2/webhooks/{id}/rotate-secret/")
.header("Idempotency-Key", "<idempotency-key>")
.header("Authorization", "Bearer <token>")
.asString();using RestSharp;
var options = new RestClientOptions("https://api.paywise.de/v2/webhooks/{id}/rotate-secret/");
var client = new RestClient(options);
var request = new RestRequest("");
request.AddHeader("Idempotency-Key", "<idempotency-key>");
request.AddHeader("Authorization", "Bearer <token>");
var response = await client.PostAsync(request);
Console.WriteLine("{0}", response.Content);
curl --request POST \
--url https://api.paywise.de/v2/webhooks/{id}/rotate-secret/ \
--header 'Authorization: Bearer <token>' \
--header 'Idempotency-Key: <idempotency-key>'{
"auto_disabled": true,
"consecutive_failures": 123,
"contract_version": "v1",
"created_at": "2023-11-07T05:31:56Z",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"last_failure_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"url": "<string>",
"description": "<string>",
"enabled": true,
"events": [
"*"
],
"max_consecutive_failures": 500,
"secret_key": "<string>"
}{
"code": "validation_error",
"detail": "The request contains invalid data.",
"errors": [
{
"code": "invalid",
"field": "claims[0].due_date",
"message": "Due date must not precede the document date."
}
]
}{
"code": "not_authenticated",
"detail": "Authentication credentials were not provided."
}{
"code": "<string>",
"detail": "<string>",
"errors": [
{
"code": "<string>",
"field": "<string>",
"message": "<string>"
}
]
}{
"code": "not_found",
"detail": "The requested resource was not found."
}{
"code": "conflict",
"detail": "The resource changed state and cannot accept this command."
}{
"code": "<string>",
"detail": "<string>",
"errors": [
{
"code": "<string>",
"field": "<string>",
"message": "<string>"
}
]
}{
"code": "<string>",
"detail": "<string>",
"errors": [
{
"code": "<string>",
"field": "<string>",
"message": "<string>"
}
]
}Rotate webhook secret
Company-scoped webhook endpoint management.
import requests
url = "https://api.paywise.de/v2/webhooks/{id}/rotate-secret/"
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Idempotency-Key': '<idempotency-key>', Authorization: 'Bearer <token>'}
};
fetch('https://api.paywise.de/v2/webhooks/{id}/rotate-secret/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));HttpResponse<String> response = Unirest.post("https://api.paywise.de/v2/webhooks/{id}/rotate-secret/")
.header("Idempotency-Key", "<idempotency-key>")
.header("Authorization", "Bearer <token>")
.asString();using RestSharp;
var options = new RestClientOptions("https://api.paywise.de/v2/webhooks/{id}/rotate-secret/");
var client = new RestClient(options);
var request = new RestRequest("");
request.AddHeader("Idempotency-Key", "<idempotency-key>");
request.AddHeader("Authorization", "Bearer <token>");
var response = await client.PostAsync(request);
Console.WriteLine("{0}", response.Content);
curl --request POST \
--url https://api.paywise.de/v2/webhooks/{id}/rotate-secret/ \
--header 'Authorization: Bearer <token>' \
--header 'Idempotency-Key: <idempotency-key>'{
"auto_disabled": true,
"consecutive_failures": 123,
"contract_version": "v1",
"created_at": "2023-11-07T05:31:56Z",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"last_failure_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"url": "<string>",
"description": "<string>",
"enabled": true,
"events": [
"*"
],
"max_consecutive_failures": 500,
"secret_key": "<string>"
}{
"code": "validation_error",
"detail": "The request contains invalid data.",
"errors": [
{
"code": "invalid",
"field": "claims[0].due_date",
"message": "Due date must not precede the document date."
}
]
}{
"code": "not_authenticated",
"detail": "Authentication credentials were not provided."
}{
"code": "<string>",
"detail": "<string>",
"errors": [
{
"code": "<string>",
"field": "<string>",
"message": "<string>"
}
]
}{
"code": "not_found",
"detail": "The requested resource was not found."
}{
"code": "conflict",
"detail": "The resource changed state and cannot accept this command."
}{
"code": "<string>",
"detail": "<string>",
"errors": [
{
"code": "<string>",
"field": "<string>",
"message": "<string>"
}
]
}{
"code": "<string>",
"detail": "<string>",
"errors": [
{
"code": "<string>",
"field": "<string>",
"message": "<string>"
}
]
}Authorizations
Company-bound Case Management API key — the standard credential for this API.
Headers
Required when a Partner key calls the Case Management API; rejected for direct Case keys. Contains the entitled paywise company UUID.
Required client-supplied command key scoped to the selected Case company or Partner owner, method, operation and path. An exact retry replays the original response while it is retained, including after credential rotation or replacement. Current permissions are required.
255Path Parameters
UUID of the webhook subscription in this request.
Response
Create / rotate-secret response — surfaces secret_key exactly once.
true when the endpoint was disabled automatically after reaching max_consecutive_failures; re-enable it with enabled: true once the destination is fixed.
Consecutive deliveries that reached terminal failure. Individual retry attempts do not increment this counter; a successful delivery resets it.
Payload/signature contract of this endpoint. Endpoints created via this API are always v2; v1 marks a legacy subscription that still receives v1 payloads and must be recreated to migrate.
v1- Legacy v1v2- Version 2
v1, v2 Time at which the webhook subscription was created.
Stable identifier for this resource.
Time of the most recent terminal delivery failure since the last successful delivery; null after a successful delivery or when no failure has been recorded.
Time at which the webhook subscription was last updated.
Publicly reachable HTTPS URL for webhook notifications. Must be unique among this company’s v2 endpoints; duplicate checks normalize the scheme, host, and default port.
2048Optional single-line label for this webhook.
255Whether deliveries are attempted. Re-enabling an endpoint resets its consecutive failure counter.
Current public event subscriptions for this endpoint. ["*"] subscribes to all public events; otherwise the list contains the subscribed event types.
*- *order.submitted- order.submittedorder.withdrawn- order.withdrawnorder.rejected- order.rejectedorder.accepted- order.acceptedorder.expired- order.expiredmandate.created- mandate.createdmandate.state.changed- mandate.state.changedmandate.status_update.published- mandate.status_update.publishedmandate.balance_updated- mandate.balance_updatedorder.message.created- order.message.createdmandate.message.created- mandate.message.createdrequest_to_client.created- request_to_client.createdrequest_to_client.answered- request_to_client.answeredpayment.reported- payment.reportedstatement.published- statement.publishedstatement.cancelled- statement.cancelledsingle_mandate_statement.published- single_mandate_statement.publishedsingle_mandate_statement.cancelled- single_mandate_statement.cancelledinvoice.created- invoice.createdinvoice.paid- invoice.paidinvoice.cancelled- invoice.cancelledinvoice.written_off- invoice.written_offdunning.level_advanced- dunning.level_advanceddunning.handed_to_collection- dunning.handed_to_collection
*, order.submitted, order.withdrawn, order.rejected, order.accepted, order.expired, mandate.created, mandate.state.changed, mandate.status_update.published, mandate.balance_updated, order.message.created, mandate.message.created, request_to_client.created, request_to_client.answered, payment.reported, statement.published, statement.cancelled, single_mandate_statement.published, single_mandate_statement.cancelled, invoice.created, invoice.paid, invoice.cancelled, invoice.written_off, dunning.level_advanced, dunning.handed_to_collection Automatically disables the endpoint when this many consecutive deliveries reach terminal failure. Retry attempts within one delivery do not each count.
1 <= x <= 1000Signing secret shown once on creation or rotation. Store it to verify webhook signatures; list, retrieve, and idempotent replay responses omit it.
