curl -X POST "https://api.dcycle.io/v2/webhook-endpoints/5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f/rotate-secret" \
-H "x-api-key: ${DCYCLE_API_KEY}" \
-H "x-organization-id: ${DCYCLE_ORG_ID}"
import os
import requests
response = requests.post(
"https://api.dcycle.io/v2/webhook-endpoints/5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f/rotate-secret",
headers={
"x-api-key": os.environ["DCYCLE_API_KEY"],
"x-organization-id": os.environ["DCYCLE_ORG_ID"],
},
timeout=30,
)
response.raise_for_status()
print(response.status_code, response.json())
const axios = require('axios');
const response = await axios.post('https://api.dcycle.io/v2/webhook-endpoints/5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f/rotate-secret', null, {
headers: {
'x-api-key': process.env.DCYCLE_API_KEY,
'x-organization-id': process.env.DCYCLE_ORG_ID,
},
});
console.log(response.status, response.data);
{
"id": "5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f",
"url": "https://erp.example.com/dcycle/webhooks",
"description": "ERP integration",
"event_types": [
"ingest_job.finished"
],
"enabled": true,
"consecutive_failures": 0,
"disabled_reason": null,
"created_at": "2026-10-01T09:12:44.512031",
"updated_at": "2026-10-01T09:12:44.512031",
"secret": "whsec_kq3v0VJ9pX2rT7mB4nL8dH1sF6gW5yC0eA3uZ9iO2tQ"
}
Rotate Webhook Secret
Replace the signing secret
POST
/
v2
/
webhook-endpoints
/
{endpoint_id}
/
rotate-secret
curl -X POST "https://api.dcycle.io/v2/webhook-endpoints/5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f/rotate-secret" \
-H "x-api-key: ${DCYCLE_API_KEY}" \
-H "x-organization-id: ${DCYCLE_ORG_ID}"
import os
import requests
response = requests.post(
"https://api.dcycle.io/v2/webhook-endpoints/5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f/rotate-secret",
headers={
"x-api-key": os.environ["DCYCLE_API_KEY"],
"x-organization-id": os.environ["DCYCLE_ORG_ID"],
},
timeout=30,
)
response.raise_for_status()
print(response.status_code, response.json())
const axios = require('axios');
const response = await axios.post('https://api.dcycle.io/v2/webhook-endpoints/5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f/rotate-secret', null, {
headers: {
'x-api-key': process.env.DCYCLE_API_KEY,
'x-organization-id': process.env.DCYCLE_ORG_ID,
},
});
console.log(response.status, response.data);
{
"id": "5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f",
"url": "https://erp.example.com/dcycle/webhooks",
"description": "ERP integration",
"event_types": [
"ingest_job.finished"
],
"enabled": true,
"consecutive_failures": 0,
"disabled_reason": null,
"created_at": "2026-10-01T09:12:44.512031",
"updated_at": "2026-10-01T09:12:44.512031",
"secret": "whsec_kq3v0VJ9pX2rT7mB4nL8dH1sF6gW5yC0eA3uZ9iO2tQ"
}
← Webhooks
Generate a new signing secret. The old one stops working at once: deploy the new secret to your server right after calling this (or accept that deliveries fail verification until you do; they are retried).
Beta. Part of the webhooks API, currently in beta. The contract may still change before general availability.
curl -X POST "https://api.dcycle.io/v2/webhook-endpoints/5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f/rotate-secret" \
-H "x-api-key: ${DCYCLE_API_KEY}" \
-H "x-organization-id: ${DCYCLE_ORG_ID}"
import os
import requests
response = requests.post(
"https://api.dcycle.io/v2/webhook-endpoints/5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f/rotate-secret",
headers={
"x-api-key": os.environ["DCYCLE_API_KEY"],
"x-organization-id": os.environ["DCYCLE_ORG_ID"],
},
timeout=30,
)
response.raise_for_status()
print(response.status_code, response.json())
const axios = require('axios');
const response = await axios.post('https://api.dcycle.io/v2/webhook-endpoints/5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f/rotate-secret', null, {
headers: {
'x-api-key': process.env.DCYCLE_API_KEY,
'x-organization-id': process.env.DCYCLE_ORG_ID,
},
});
console.log(response.status, response.data);
{
"id": "5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6f",
"url": "https://erp.example.com/dcycle/webhooks",
"description": "ERP integration",
"event_types": [
"ingest_job.finished"
],
"enabled": true,
"consecutive_failures": 0,
"disabled_reason": null,
"created_at": "2026-10-01T09:12:44.512031",
"updated_at": "2026-10-01T09:12:44.512031",
"secret": "whsec_kq3v0VJ9pX2rT7mB4nL8dH1sF6gW5yC0eA3uZ9iO2tQ"
}
Request
Headers
string
required
API key of an organization admin.Example:
sk_live_1234567890abcdefstring
required
The organization that owns the endpoints.Example:
a8315ef3-dd50-43f8-b7ce-d839e68d51faPath Parameters
uuid
required
The endpoint
id.Example: 5c9e2f14-8b7a-4d3e-9f60-1a2b3c4d5e6fResponse
The endpoint and its new secret (200 OK):
uuid
Endpoint id.
string
Where the events are sent.
string | null
Free text to recognize the endpoint.
array[string]
Subscribed events. Available values:
ingest_job.finished.boolean
Disabled endpoints receive nothing.
integer
Deliveries in a row that ended
failed. At 5 the endpoint is disabled.string | null
TOO_MANY_FAILURES when Dcycle disabled the endpoint; null otherwise.datetime
UTC.
datetime
UTC.
string
Signing secret (
whsec_…). Shown only in this response: store it to verify signatures.Common Errors
401 Unauthorized
Missing or invalid API key.403 Forbidden
ORG_ADMIN_REQUIRED: only organization admins can manage webhook endpoints. LOGGED_USER_NOT_MEMBER: the API key’s user is not a member of the organization.
404 Not Found
The endpoint does not exist or belongs to another organization. Both cases return the same response.Related Endpoints
Webhooks
Verifying the signature
Send Test Event
Check the new secret
Was this page helpful?