rotate_webhook_endpoint_secret
Rotate a webhook endpoint's signing secret
All MCP toolsWrite
Mint a NEW mw_whsec_* signing secret for one endpoint and return it ONCE — the old secret stops signing immediately, so update the consumer's verifier with the returned value right away. Use after a suspected leak or when the stored secret was lost.
Input schema
{
"type": "object",
"properties": {
"endpointId": {
"type": "string",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
"description": "The endpoint to rotate (webhook_endpoints.id)."
}
},
"required": [
"endpointId"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}Output schema
{
"type": "object",
"properties": {
"endpoint": {
"type": "object",
"properties": {
"id": {
"type": "string",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
"description": "The endpoint id (webhook_endpoints.id)."
},
"jobId": {
"type": "string",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
"description": "The job whose events this endpoint receives (jobs.id)."
},
"url": {
"type": "string",
"format": "uri",
"description": "The delivery target (https, public address — SSRF-guarded); unique per job."
},
"kinds": {
"anyOf": [
{
"minItems": 1,
"type": "array",
"items": {
"type": "string",
"enum": [
"approval_pending",
"message_received",
"mutual_interest",
"interview_schedule_updated",
"candidacy_stage_changed",
"approval_decided",
"job_published",
"evaluation_requested",
"evaluation_reminder",
"candidacy_advance_pending",
"interview_slot_responded",
"counter_request_received",
"counter_request_resolved",
"interview_completed",
"interview_result_recorded",
"interview_reminder",
"interview_debrief_reminder",
"interview_slot_response_nudge",
"interview_slot_confirmation_nudge",
"job_matching_paused",
"material_request_received",
"material_request_answered",
"material_request_resolved",
"agreement_answered",
"proposal_requested",
"interview_cancelled"
]
},
"description": "Non-empty subset of the job-scoped notification kinds to deliver; null/omitted = all job-scoped kinds."
},
{
"type": "null"
}
],
"description": "Subscribed job-scoped notification kinds; null = all job-scoped kinds."
},
"active": {
"type": "boolean",
"description": "Whether deliveries fan out to this endpoint (auto-disable clears it)."
},
"autoDisabledAt": {
"anyOf": [
{
"type": "string",
"format": "date-time",
"pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d(?::[0-5]\\d(?:\\.\\d+)?)?(?:Z))$"
},
{
"type": "null"
}
],
"description": "Set when consecutive permanent failures crossed the auto-disable threshold; re-enable with update_webhook_endpoint { active: true }."
},
"consecutiveFailures": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991,
"description": "Consecutive permanent delivery failures since the last success."
},
"lastAttemptAt": {
"anyOf": [
{
"type": "string",
"format": "date-time",
"pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d(?::[0-5]\\d(?:\\.\\d+)?)?(?:Z))$"
},
{
"type": "null"
}
],
"description": "When the newest delivery attempt ran (ISO 8601, UTC); null = never attempted."
},
"createdAt": {
"type": "string",
"format": "date-time",
"pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d(?::[0-5]\\d(?:\\.\\d+)?)?(?:Z))$",
"description": "When the endpoint was registered (ISO 8601, UTC)."
}
},
"required": [
"id",
"jobId",
"url",
"kinds",
"active",
"autoDisabledAt",
"consecutiveFailures",
"lastAttemptAt",
"createdAt"
],
"additionalProperties": false,
"description": "One outbound-webhook endpoint: one job's egress configuration, secret NEVER included — it is shown once at create/rotate time only."
},
"secret": {
"type": "string",
"pattern": "^mw_whsec_[A-Za-z0-9_-]+$",
"description": "The endpoint's signing secret (mw_whsec_*) — shown ONCE in this response; store it now. Verify deliveries by recomputing HMAC-SHA256 over '<t>.<body>' with it."
}
},
"required": [
"endpoint",
"secret"
],
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false
}