Skip to the page
Chapters

Webhook endpoints

Rotate a signing secret

POST/api/v1/webhook_endpoints/{id}/rotate_secret

Replaces the endpoint's signing secret: events are signed with the new secret from now on, and the old one stops working at once. Send an empty JSON object as the body. The response carries the signing secret (secret). It is shown only in this response and cannot be read again: store it now. A request repeated with the same Idempotency-Key gets the stored reply without the secret (secret_available is false): rotate the secret to get a new one.

Needs a key with submit permission.

Request

Headers

Headers
NameTypeRequiredDescription
Idempotency-KeystringrequiredMakes the request safe to repeat: a request with the same key and body returns the first answer (the reply has an idempotent-replayed header), and the same key with a different request is refused. 1 to 255 printable characters; a UUID is a good choice.At least 1 character.At most 255 characters.Matches `^[\x21-\x7e]{1,255}$`.

Path parameters

Path parameters
NameTypeRequiredDescription
idstringrequiredA webhook endpoint ID (whe_...).

Response

The endpoint, with its new signing secret. Status 200.

Response fields
NameTypeDescription
idstringAn ID that starts with whe_.
objectstringAlways `webhook_endpoint`.
urlstring
descriptionstring
event_typesarray of string or nullThe event types sent to this endpoint; null for every type.Each item is one of: `eligibility.completed`, `api_key.created`, `api_key.revoked`, `claim.validated`, `claim.needs_attention`, `claim.queued`, `claim.submitted`, `claim.accepted`, `claim.rejected`, `claim.status_updated`, `claim.voided`, `batch.acknowledged`, `attachment.completed`, `payer_request.received`, `era.received`, `claim.paid`, `claim.denied`, `claim.payment_reversed`, `predetermination.returned`.
statusstringOne of: `enabled`, `disabled`.
modestringOne of: `test`, `live`.
created_atstring (date-time)
secretstringThe signing secret (whsec_...). Shown only in the response that made it: store it now. Absent when secret_available is false.
secret_availablebooleanFalse in the stored reply an Idempotency-Key replay returns: the secret is never stored for replay. Rotate the secret to get a new one.

Errors

Errors
HTTP statusCodeWhat it means
401UNAUTHORIZEDA valid API key is required. Send it as "Authorization: Bearer <key>".
403PERMISSION_DENIEDThis API key is not allowed to do that.
404NOT_FOUNDNot found.
422INVALID_REQUESTThe request is not valid.
400IDEMPOTENCY_KEY_REQUIREDPOST and PATCH requests need an Idempotency-Key header.
422IDEMPOTENCY_KEY_REUSEDThat Idempotency-Key was already used with a different request.
409IDEMPOTENCY_KEY_IN_USEA request with that Idempotency-Key is still running. Retry shortly.
413PAYLOAD_TOO_LARGEThe request body is larger than 1 MB.
504TIMEOUTThe request took too long to finish. It may still have taken effect: look it up before sending it again with a new Idempotency-Key. What it made is found with GET /api/v1/eligibility?request_id=<this request_id>, and the same filter on /api/v1/claims and /api/v1/attachments (a key with read permission).
500INTERNALSomething went wrong on our side. Quote the request ID if you contact us.

Example

Example request

Shell
curl -X POST "https://sandbox.myclaimhouse.com/api/v1/webhook_endpoints/whe_01JM000000E008000000000021/rotate_secret" \
  -H "Authorization: Bearer $CLAIMHOUSE_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{}'

Example response: 200

JSON
{
  "id": "whe_01JM000000E008000000000021",
  "object": "webhook_endpoint",
  "url": "https://hooks.example.com/claimhouse",
  "description": "Billing system",
  "event_types": [
    "eligibility.completed"
  ],
  "status": "enabled",
  "mode": "test",
  "created_at": "2026-03-10T15:00:00.000000+00:00",
  "secret": "whsec_EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEE",
  "secret_available": true
}