Webhook endpoints
Rotate a signing secret
POST/api/v1/webhook_endpoints/{id}/rotate_secret
Replaces the endpoint's signing secret: events are signed with the new secret from now on, and the old one stops working at once. Send an empty JSON object as the body. The response carries the signing secret (secret). It is shown only in this response and cannot be read again: store it now. A request repeated with the same Idempotency-Key gets the stored reply without the secret (secret_available is false): rotate the secret to get a new one.
Needs a key with submit permission.
Request
Headers
| Name | Type | Required | Description |
|---|---|---|---|
| Idempotency-Key | string | required | Makes the request safe to repeat: a request with the same key and body returns the first answer (the reply has an idempotent-replayed header), and the same key with a different request is refused. 1 to 255 printable characters; a UUID is a good choice.At least 1 character.At most 255 characters.Matches `^[\x21-\x7e]{1,255}$`. |
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
| id | string | required | A webhook endpoint ID (whe_...). |
Response
The endpoint, with its new signing secret. Status 200.
| Name | Type | Description |
|---|---|---|
| id | string | An ID that starts with whe_. |
| object | string | Always `webhook_endpoint`. |
| url | string | |
| description | string | |
| event_types | array of string or null | The event types sent to this endpoint; null for every type.Each item is one of: `eligibility.completed`, `api_key.created`, `api_key.revoked`, `claim.validated`, `claim.needs_attention`, `claim.queued`, `claim.submitted`, `claim.accepted`, `claim.rejected`, `claim.status_updated`, `claim.voided`, `batch.acknowledged`, `attachment.completed`, `payer_request.received`, `era.received`, `claim.paid`, `claim.denied`, `claim.payment_reversed`, `predetermination.returned`. |
| status | string | One of: `enabled`, `disabled`. |
| mode | string | One of: `test`, `live`. |
| created_at | string (date-time) | |
| secret | string | The signing secret (whsec_...). Shown only in the response that made it: store it now. Absent when secret_available is false. |
| secret_available | boolean | False in the stored reply an Idempotency-Key replay returns: the secret is never stored for replay. Rotate the secret to get a new one. |
Errors
| HTTP status | Code | What it means |
|---|---|---|
| 401 | UNAUTHORIZED | A valid API key is required. Send it as "Authorization: Bearer <key>". |
| 403 | PERMISSION_DENIED | This API key is not allowed to do that. |
| 404 | NOT_FOUND | Not found. |
| 422 | INVALID_REQUEST | The request is not valid. |
| 400 | IDEMPOTENCY_KEY_REQUIRED | POST and PATCH requests need an Idempotency-Key header. |
| 422 | IDEMPOTENCY_KEY_REUSED | That Idempotency-Key was already used with a different request. |
| 409 | IDEMPOTENCY_KEY_IN_USE | A request with that Idempotency-Key is still running. Retry shortly. |
| 413 | PAYLOAD_TOO_LARGE | The request body is larger than 1 MB. |
| 504 | TIMEOUT | The request took too long to finish. It may still have taken effect: look it up before sending it again with a new Idempotency-Key. What it made is found with GET /api/v1/eligibility?request_id=<this request_id>, and the same filter on /api/v1/claims and /api/v1/attachments (a key with read permission). |
| 500 | INTERNAL | Something went wrong on our side. Quote the request ID if you contact us. |
Example
Example request
curl -X POST "https://sandbox.myclaimhouse.com/api/v1/webhook_endpoints/whe_01JM000000E008000000000021/rotate_secret" \
-H "Authorization: Bearer $CLAIMHOUSE_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{}'Example response: 200
{
"id": "whe_01JM000000E008000000000021",
"object": "webhook_endpoint",
"url": "https://hooks.example.com/claimhouse",
"description": "Billing system",
"event_types": [
"eligibility.completed"
],
"status": "enabled",
"mode": "test",
"created_at": "2026-03-10T15:00:00.000000+00:00",
"secret": "whsec_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEE",
"secret_available": true
}