@firma-dev/sdk
import { FirmaClient } from "@firma-dev/sdk";
const firma = new FirmaClient({ apiKey: "YOUR_API_KEY" });
const response = await firma.webhooks.rotateWebhookSecret();
console.log(response);curl --request POST \
--url https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret \
--header 'Authorization: <api-key>'import requests
url = "https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret"
headers = {"Authorization": "<api-key>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: '<api-key>'}};
fetch('https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret")
.header("Authorization", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"message": "Webhook secret rotated successfully",
"new_secret": "a1b2c3d4e5f6...",
"grace_period_hours": 168,
"warning": "Update your webhook signature verification to use the new secret. The old secret will remain valid for 7 days."
}{
"error": "Unauthorized",
"message": "Invalid API key"
}{
"error": "<string>",
"message": "<string>",
"details": {}
}Webhooks
Faire tourner le secret de signature du webhook
Génère un nouveau secret de signature de webhook pour l’entreprise. L’ancien secret reste valide pendant 7 jours pour permettre une migration en douceur. Limité à 1 requête par minute.
POST
/
webhooks
/
rotate-secret
@firma-dev/sdk
import { FirmaClient } from "@firma-dev/sdk";
const firma = new FirmaClient({ apiKey: "YOUR_API_KEY" });
const response = await firma.webhooks.rotateWebhookSecret();
console.log(response);curl --request POST \
--url https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret \
--header 'Authorization: <api-key>'import requests
url = "https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret"
headers = {"Authorization": "<api-key>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: '<api-key>'}};
fetch('https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret")
.header("Authorization", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.firma.dev/functions/v1/signing-request-api/webhooks/rotate-secret")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"message": "Webhook secret rotated successfully",
"new_secret": "a1b2c3d4e5f6...",
"grace_period_hours": 168,
"warning": "Update your webhook signature verification to use the new secret. The old secret will remain valid for 7 days."
}{
"error": "Unauthorized",
"message": "Invalid API key"
}{
"error": "<string>",
"message": "<string>",
"details": {}
}Autorisations
Clé API pour l'authentification. Utilisez votre clé API directement sans préfixe (par exemple, 'your-api-key'). Le préfixe Bearer est optionnel mais pas obligatoire.
Réponse
Secret changé avec succès
Résultat de la rotation du secret avec période de grâce
Le nouveau secret de signature du webhook (chaîne hexadécimale de 64 caractères)
Nombre d'heures pendant lesquelles l'ancien secret reste valide en parallèle du nouveau
Rappel de mettre à jour la vérification de signature du webhook
Cette page vous a-t-elle été utile ?
⌘I