1. Webhooks
uploadthefile API documentation
  • Pages
    • Create a page
      POST
    • Update a page in place
      PUT
    • List pages
      GET
    • Get a page
      GET
    • Rename a page
      PATCH
    • Delete a page
      DELETE
    • Unzip & host a page
      POST
    • List a hosted site's files
      GET
    • Apply a batch of file changes
      POST
    • Replace one file
      PUT
    • Delete one file
      DELETE
    • Get page password state
      GET
    • Set page password
      PUT
    • Remove page password
      DELETE
    • Get page expiry
      GET
    • Set page expiry
      PUT
    • Get email-gate config
      GET
    • Configure email-gate
      PUT
    • Disable email-gate
      DELETE
    • List or export captured emails
      GET
    • Erase captured emails
      DELETE
    • Get page display mode
      GET
    • Set page display mode
      PUT
    • Get PDF chat availability
      GET
    • Enable PDF chat
      PUT
    • Disable PDF chat
      DELETE
    • Bulk delete pages
      POST
  • Short links
    • List short links
    • Create a short link
    • Bulk update short links
    • Get a short link
    • Update a short link
    • Delete a short link
    • Get link click history
  • Domains
    • List custom domains
    • Connect a custom domain
    • Search domain availability
    • Rebind a domain to a different page
    • Disconnect a domain
  • Account
    • Get account, limits, and usage
  • Team
    • List team members
    • Invite a team member
    • Revoke a team member
    • Change a team member's role
    • Resend a pending invite
  • AI connectors
    • Authorization server metadata
    • Protected resource metadata (MCP endpoint)
    • Protected resource metadata (RFC 9728 §3.1 path-insertion form)
    • Register an OAuth client
    • Authorization endpoint (consent screen)
    • Consent decision (internal, not a public integration point)
    • Token endpoint
    • Revocation endpoint
    • MCP endpoint
  • Subjects
    • List subjects
    • Create or get a subject
    • Get a subject
    • Update a subject
    • Delete (tombstone) a subject
  • Subject tokens
    • Mint a subject token
    • Revoke a subject's tokens
  • Sites
    • List a subject's sites
    • Create a site for a subject
    • Get a site
    • Apply a batch of file changes
    • Delete a site
    • List a site's files
    • Read one file's content
  • Usage
    • Per-subject usage for a period
  • Webhooks
    • List webhook endpoints
      GET
    • Register a webhook endpoint
      POST
    • Get a webhook endpoint
      GET
    • Update a webhook endpoint
      PATCH
    • Delete a webhook endpoint
      DELETE
    • Rotate an endpoint's signing secret
      POST
    • List deliveries (the delivery log)
      GET
    • Replay a delivery
      POST
    • Poll event history (no endpoint required)
      GET
  • Schemas
    • UploadCreateForm
    • PlatformSubject
    • UploadUpdateForm
    • SubjectCreateRequest
    • SubdomainName
    • SubjectPatchRequest
    • RenamePageRequest
    • SubjectMintRequest
    • CreateLinkRequest
    • SubjectEnvelope
    • UpdateLinkRequest
    • SubjectListEnvelope
    • BulkDeletePagesRequest
    • SubjectDeleteEnvelope
    • BulkLinkActionRequest
    • SubjectMintEnvelope
    • ClickPoint
    • SubjectRevokeEnvelope
    • DisplayMode
    • Site
    • SetDisplayModeRequest
    • SiteCreateRequest
    • SetPasswordRequest
    • SitePatchRequest
    • SetEmailGateRequest
    • SiteFile
    • EmailCapture
    • SiteEnvelope
    • ConnectDomainRequest
    • SiteListEnvelope
    • RebindDomainRequest
    • SitePatchEnvelope
    • DomainConnection
    • SiteDeleteEnvelope
    • SiteFilesEnvelope
    • DomainSearchResult
    • UsageSubject
    • SiteFileContentEnvelope
    • LinkCode
    • UsageSubjectsEnvelope
    • ExpiryOption
    • WebhookEventType
    • ApiPage
    • WebhookEndpoint
    • ShortLink
    • WebhookEndpointCreateRequest
    • AccountInfo
    • WebhookEndpointPatchRequest
    • TeamMember
    • WebhookEndpointEnvelope
    • SeatUsage
    • WebhookEndpointSecretEnvelope
    • InviteMemberRequest
    • WebhookEndpointListEnvelope
    • UpdateMemberRoleRequest
    • WebhookEndpointDeleteEnvelope
    • ResendCooldownError
    • WebhookDelivery
    • UploadResult
    • WebhookDeliveryListEnvelope
    • HostResult
    • WebhookReplayEnvelope
    • DeleteResult
    • WebhookEvent
    • UpgradeNudge
    • WebhookEventListEnvelope
    • UploadResultEnvelope
    • Error
    • PageEnvelope
    • PagesListEnvelope
    • HostEnvelope
    • DeleteEnvelope
    • ProjectFile
    • LinkEnvelope
    • ProjectFilesEnvelope
    • LinksListEnvelope
    • AccountEnvelope
    • TeamMembersEnvelope
    • TeamMemberEnvelope
    • RevokeMemberEnvelope
    • BulkAffectedEnvelope
    • BulkDeletedEnvelope
    • PagePasswordStateEnvelope
    • ClickSeriesEnvelope
    • PagePasswordResultEnvelope
    • EmailGateStateEnvelope
    • EmailGateUpdatedEnvelope
    • EmailGateDisabledEnvelope
    • CapturesEnvelope
    • DisplayModeStateEnvelope
    • DisplayModeResultEnvelope
    • DeleteCapturesRequest
    • CapturesDeletedEnvelope
    • DomainConnectionEnvelope
    • DomainDeletedEnvelope
    • ChatAvailabilityEnvelope
    • DomainSearchEnvelope
    • DomainsListEnvelope
    • OAuthError
    • OAuthAuthorizationServerMetadata
    • OAuthProtectedResourceMetadata
    • OAuthClientRegistrationRequest
    • OAuthClientRegistrationResponse
    • OAuthTokenRequest
    • OAuthTokenResponse
  1. Webhooks

Rotate an endpoint's signing secret

POST
/webhooks/endpoints/{endpointId}/rotate-secret
Mints a fresh signing secret. The outgoing secret keeps signing
deliveries alongside the new one for a 24-hour overlap window (during
which webhook-signature carries two v1,<sig> pairs), so you have
real time to roll the new value into your receiver's verification
before the old one stops working. The new raw secret is returned
exactly once, in this response only.

Request

Authorization
API Key
Add parameter in header
x-api-key
Example:
x-api-key: ********************
or
Bearer Token
Provide your bearer token in the
Authorization
header when making requests to protected resources.
Example:
Authorization: Bearer ********************
or
Path Params

Responses

🟢200OK
application/json
The secret was rotated.
Bodyapplication/json

🟠401Unauthorized
🟠403Forbidden
🟠404Record Not Found
🟠429
Request Request Example
Shell
JavaScript
Java
Swift
curl --location --request POST 'https://upload.tf/api/v1/webhooks/endpoints//rotate-secret' \
--header 'x-api-key: <api-key>'
Response Response Example
200 - Example 1
{
    "success": true,
    "data": {
        "endpoint": {
            "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
            "url": "http://example.com",
            "eventTypes": [
                "page.published"
            ],
            "apiVersion": "2026-08-08",
            "enabled": true,
            "consecutiveFailures": 0,
            "lastSuccessAt": "2019-08-24T14:15:22.123Z",
            "lastFailureAt": "2019-08-24T14:15:22.123Z",
            "lastAttemptAt": "2019-08-24T14:15:22.123Z",
            "disabledAt": "2019-08-24T14:15:22.123Z",
            "disabledReason": "string",
            "createdAt": "2019-08-24T14:15:22.123Z",
            "updatedAt": "2019-08-24T14:15:22.123Z"
        },
        "secret": "string"
    }
}
Modified at 2026-08-18 09:08:48
Previous
Delete a webhook endpoint
Next
List deliveries (the delivery log)
Built with