Set or rotate a webhook secret

POST/v1/campaigns/{campaign_id}/webhooks/{webhook_id}/secret
Scope: campaigns:write

Sets or replaces the secret used to sign this webhook's deliveries. Each delivery then carries X-Signature-256: sha256=<hex>, an HMAC-SHA256 of the exact request body keyed with the secret.

Send your own secret, or leave it out and one is generated. Use this to add signing to a webhook created without a secret, or to replace a secret you think is compromised.

A generated secret appears in this response and nowhere else. Store it before you discard the response.

Headers

  • AuthorizationstringRequired

    Bearer followed by a space and your API key, for example Bearer vk_….

Path parameters

  • campaign_idstring · uuidRequired

    ID of the campaign.

  • webhook_idstring · uuidRequired

    ID of the webhook.

Request body

  • secretstring or null

    Your own signing key, so both sides hold the same value. Omit it and one is generated and returned once.

    at least 16 charactersat most 2,000 characters

Response

200

  • webhook_idstringRequired

    ID of the webhook whose secret was rotated

  • messagestring
    Default "Webhook signing secret rotated"
  • secretstring or null

    Present only when the secret was generated server-side, and only in this response: store it now, it cannot be retrieved again. Absent when you supplied your own.

  • successboolean
    Default true

Errors

Errors share one JSON body: success, error, message, optional details, and request_id.

StatusCodeMeaning
400VALIDATION_ERROR

The request didn't match the endpoint's schema: a missing or malformed field, a bad query parameter, or a value out of range. details.errors lists each failing field with its field, message and type.

401UNAUTHORIZED

The Authorization header is missing or malformed, or the API key is unknown or has been deactivated.

401API_KEY_EXPIRED

The API key is past its expiry date. Create a new key in the Victoria AI app.

403INSUFFICIENT_SCOPE

The API key doesn't have the scope this endpoint requires, such as leads:write.

403ORGANIZATION_DEACTIVATED

The organization that owns this API key has been deactivated.

404CAMPAIGN_NOT_FOUND

No campaign with this ID exists in your organization.

404WEBHOOK_NOT_FOUND

No webhook with this ID exists on the campaign.

404NOT_FOUND

No endpoint matches the path. A resource ID in the path that isn't a valid UUID also answers NOT_FOUND.

413PAYLOAD_TOO_LARGE

The request body is larger than 1 MB.

429RATE_LIMITED

Too many requests for this API key: more than 100 a minute to one endpoint, or 600 a minute in total. Retry after the number of seconds in the Retry-After header. See Rate limits.

500INTERNAL_ERROR

Something failed on our side. The response never includes internal details; quote its request_id when you contact support.

503UPSTREAM_TIMEOUT

A service the API depends on timed out. The request is safe to retry.

503AUTH_UNAVAILABLE

The API key couldn't be checked because the authentication service was unavailable. The request is safe to retry.

Response headers

HeaderDescription
X-Request-ID

Correlation ID for the request, also returned as request_id in error bodies. Send your own X-Request-ID, up to 128 letters, digits, ., _, : or -, and it's used instead.

RateLimit-Limit

Requests allowed to this endpoint per minute.

RateLimit-Remaining

Requests you can still send to this endpoint right now.

RateLimit-Reset

Seconds until the endpoint's full limit is available again.

Retry-After

On a 429: seconds to wait before retrying.