Skip to main content
POST
Rotate the webhook signing secret

Authorizations

Authorization
string
header
required

Locus Pro dashboard session (Cognito). High-risk workspace administration requires an owner or admin role and fresh MFA/passkey step-up.

Headers

X-Locus-Step-Up
string<password>

Short-lived raw MFA/passkey step-up token bound to the authenticated Cognito subject. Send it alongside the dashboard Bearer token for workspace-administrator mutations when the base session does not itself prove MFA within the last ten minutes. Never send it with a tenant secret key.

Response

200 - application/json

New signing secret and old-secret expiry

success
any
required
webhook_secret
string
required
Pattern: ^whsec_
previous_secret_valid_until
string<date-time>
required