Requires scope webhook:write.
One secret per tenant, covering every webhook you have registered. CLC signs
each delivery with it so you can tell a real delivery from a forged one.
Creating a second secret destroys the first immediately, and there is no
overlap window. Deploy the new value to your endpoint in the same window you
create it, or you will reject your own deliveries in between.
Until a secret exists, deliveries go out unsigned and you have no way to
authenticate them. Create it before you register any webhook.
Idempotency-Key matters more here than anywhere else in the API: without it,
a client retry on a timed-out request rotates the secret a second time and the
value from the first attempt is gone for good.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||