Skip to content

Create a signing secret

POST
/webhook-secrets
curl --request POST \
--url https://api.sendtruss.com/v1/webhook-secrets \
--header 'Authorization: Bearer <token>'

The response carries the secret once and never again. To rotate, create a new one, switch your verification to it, then revoke the old one. You can have up to 3.

Media typeapplication/json
object
data
required
object
id
required
string
secret
required
string
last_four
required
string
created_at
required
string | null
Examplegenerated
{
"data": {
"id": "example",
"secret": "example",
"last_four": "example",
"created_at": "example"
}
}
Request-Id
required
string format: uuid

This request’s id. Quote it when you ask us about the request.

The API key is missing, malformed, revoked or expired.

Media typeapplication/json
object
message
required

What went wrong, for a person to read. It may change, so branch on code.

string
code
required

What went wrong, for your code to branch on. A new code is not a breaking change.

string
Allowed values: unauthenticated
doc_url
required

The entry on our errors page that explains this code.

string format: uri
request_id
required

This request’s id, the same as its Request-Id header. Quote it when you ask us about the request.

string format: uuid
Example
{
"code": "unauthenticated"
}
Request-Id
required
string format: uuid

This request’s id. Quote it when you ask us about the request.

Refused because of the resource’s current state. The code says why.

Media typeapplication/json
object
message
required

What went wrong, for a person to read. It may change, so branch on code.

string
code
required

What went wrong, for your code to branch on. A new code is not a breaking change.

string
Allowed values: secret_ceiling_reached
doc_url
required

The entry on our errors page that explains this code.

string format: uri
request_id
required

This request’s id, the same as its Request-Id header. Quote it when you ask us about the request.

string format: uuid
Example
{
"code": "secret_ceiling_reached"
}
Request-Id
required
string format: uuid

This request’s id. Quote it when you ask us about the request.

Too many requests. Wait for the seconds in Retry-After.

Media typeapplication/json
object
message
required

What went wrong, for a person to read. It may change, so branch on code.

string
code
required

What went wrong, for your code to branch on. A new code is not a breaking change.

string
Allowed values: rate_limited
doc_url
required

The entry on our errors page that explains this code.

string format: uri
request_id
required

This request’s id, the same as its Request-Id header. Quote it when you ask us about the request.

string format: uuid
Example
{
"code": "rate_limited"
}
Request-Id
required
string format: uuid

This request’s id. Quote it when you ask us about the request.

Retry-After
integer

Seconds to wait before trying again.