ZyloPaydocs
Webhook endpoints

Rotate the signing secret

Issue a new signing secret (returned once).

POST/v1/webhook_endpoints/{id}/rotate_secretscope webhooks:manage

For expires_in_hours (default 24) deliveries carry two v1 signatures — new and previous secret — so you can deploy the new secret without dropping events.

Path parameters

idstringrequired

Webhook endpoint ID (we_…).

Body parameters

expires_in_hoursintegerdefault 24

How long the previous secret keeps signing deliveries alongside the new one (0-168 hours). 0 stops it at once.

Headers

ZyloPay-Versionstring

Pin the request to an API version (2026-09-28). Defaults to the version the API key was created with.

Idempotency-Keystring

Recommended. A unique key per operation (a UUID v4); retries with the same key and body return the first response.

Returns

HTTP 200 with the webhook endpoint object.

Errors

StatusMeaning
400Invalid request (invalid_request_error / idempotency_error).
401Missing, invalid, expired or revoked API key (authentication_error).
403The key lacks the scope, the IP is not allowed, or the account is disabled (permission_error).
409Conflict: idempotency key reused or in progress, or the object is in the wrong state.
429Rate limit reached for this key (rate_limit_error); see Retry-After.
500Internal error (api_error). Retry with the same Idempotency-Key.

Branch on error.code. Every code is listed in error codes.

Example request

curl https://zylopay-api.fly.dev/api/v1/webhook_endpoints/we_2Lk9Qm4Xz7Pv1Rt8Wb3Ns6Hd/rotate_secret \
  -H "Authorization: Bearer $ZYLOPAY_SECRET_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
    "expires_in_hours": 48
  }'

Example response

{
  "id": "we_2Lk9Qm4Xz7Pv1Rt8Wb3Ns6Hd",
  "object": "webhook_endpoint",
  "livemode": false,
  "url": "https://example.com/zylopay/webhooks",
  "description": "Order service (test)",
  "enabled_events": [
    "payment.succeeded",
    "payment_intent.*",
    "refund.*"
  ],
  "status": "enabled",
  "disabled_reason": null,
  "api_version": "2026-09-28",
  "failing_since": null,
  "last_success_at": "2026-09-28T14:02:41.000Z",
  "secret_rotation_ends_at": "2026-09-30T10:00:00.000Z",
  "created": "2026-09-20T10:00:00.000Z",
  "updated": "2026-09-28T10:00:00.000Z",
  "secret": "whsec_Qp4Io3Ue2Ya9Jc0Fg5Hd6Ns1Tb8Rv4Pw7Lm2Kq9Zx3b"
}

On this page