Hooks
Rotate Hook Secret
Replace the secret that signs the webhook deliveries of a hook
POST
/
lending-external-securities-v2
/
api
/
hooks
/
{marketId}
/
{hookId}
/
rotate-secret
curl -X POST "https://api.trusset.org/lending-external-securities-v2/api/hooks/{marketId}/{hookId}/rotate-secret" \
-H "X-API-Key: trusset_your_key_here"
const res = await fetch(
`https://api.trusset.org/lending-external-securities-v2/api/hooks/${marketId}/${hookId}/rotate-secret`,
{ method: 'POST', headers: { 'X-API-Key': 'trusset_your_key_here' } }
);
const { data } = await res.json();
const webhookSecret: string = data.webhookSecret;
{
"success": true,
"data": {
"id": "hook_004",
"webhookSecret": "7350b6c5815644ebd5ff51d3ef2d32f6fe700cfa210f14bba8699b199d6fc52e",
"rotatedAt": "2026-10-10T09:30:00.000Z"
},
"error": null,
"metadata": {
"timestamp": "2026-10-10T09:30:00.000Z",
"requestId": "550e8400-e29b-41d4-a716-446655440000",
"instanceId": "inst_abc123"
}
}
{
"success": false,
"data": null,
"error": {
"code": "HOOK_NOT_FOUND",
"message": "Hook not found"
}
}
Replaces the hook’s signing secret with a new random one and returns it. This response is the only place the new secret appears: hook reads carry
Create Hook issues a secret to every hook it creates, but only an
signed, never the secret. Nothing goes on-chain.
The previous secret stops at once, with no overlap. Every attempt sent after this call is signed with the new secret, including retries of deliveries queued before it. A receiver that rejects a signature with a
4xx other than 408, 425 or 429 fails that delivery for good. Switch the receiver to the new secret right away, or have it answer a retried status such as 503 while it switches.inform action sends deliveries, so the secret is used only there. A hook whose signed reads false holds no secret, and its deliveries carry no x-webhook-signature. Rotating issues it one, and every attempt from then on is signed. Signed deliveries describes how the signature is computed.
The request takes no body.
Path Parameters
string
required
string
required
Hook ID.
Response Fields
object
curl -X POST "https://api.trusset.org/lending-external-securities-v2/api/hooks/{marketId}/{hookId}/rotate-secret" \
-H "X-API-Key: trusset_your_key_here"
const res = await fetch(
`https://api.trusset.org/lending-external-securities-v2/api/hooks/${marketId}/${hookId}/rotate-secret`,
{ method: 'POST', headers: { 'X-API-Key': 'trusset_your_key_here' } }
);
const { data } = await res.json();
const webhookSecret: string = data.webhookSecret;
{
"success": true,
"data": {
"id": "hook_004",
"webhookSecret": "7350b6c5815644ebd5ff51d3ef2d32f6fe700cfa210f14bba8699b199d6fc52e",
"rotatedAt": "2026-10-10T09:30:00.000Z"
},
"error": null,
"metadata": {
"timestamp": "2026-10-10T09:30:00.000Z",
"requestId": "550e8400-e29b-41d4-a716-446655440000",
"instanceId": "inst_abc123"
}
}
{
"success": false,
"data": null,
"error": {
"code": "HOOK_NOT_FOUND",
"message": "Hook not found"
}
}
Error Codes
| Code | HTTP | Cause |
|---|---|---|
MISSING_MARKET_ID | 400 | marketId is longer than 100 characters |
MISSING_HOOK_ID | 400 | hookId is longer than 100 characters |
MARKET_NOT_FOUND | 404 | No market with this ID belongs to your instance |
HOOK_NOT_FOUND | 404 | No hook with this ID exists on this market |
⌘I
curl -X POST "https://api.trusset.org/lending-external-securities-v2/api/hooks/{marketId}/{hookId}/rotate-secret" \
-H "X-API-Key: trusset_your_key_here"
const res = await fetch(
`https://api.trusset.org/lending-external-securities-v2/api/hooks/${marketId}/${hookId}/rotate-secret`,
{ method: 'POST', headers: { 'X-API-Key': 'trusset_your_key_here' } }
);
const { data } = await res.json();
const webhookSecret: string = data.webhookSecret;
{
"success": true,
"data": {
"id": "hook_004",
"webhookSecret": "7350b6c5815644ebd5ff51d3ef2d32f6fe700cfa210f14bba8699b199d6fc52e",
"rotatedAt": "2026-10-10T09:30:00.000Z"
},
"error": null,
"metadata": {
"timestamp": "2026-10-10T09:30:00.000Z",
"requestId": "550e8400-e29b-41d4-a716-446655440000",
"instanceId": "inst_abc123"
}
}
{
"success": false,
"data": null,
"error": {
"code": "HOOK_NOT_FOUND",
"message": "Hook not found"
}
}
