Update webhook subscription
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Path parameters
Headers
Optional client-generated idempotency token (recommended for safe retries).
Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).
Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.
Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.
Request
Omit to leave authentication untouched. Send NONE to delete the stored HMAC key and stop signing deliveries. Any value other than HMAC or NONE is rejected.
New HMAC key. The current key is never returned, so leaving this out keeps it as is — send a value only to rotate the key.
Response
Account this subscription is bound to. null means tenant-wide: it receives every account’s events.