Replaces a destination in place. The id is immutable, because the custody reference is
derived from it.
Omit the signing secret, or send the mask sentinel, to leave the sealed secret
untouched — which is what lets a console round-trip its form without asking the
operator to retype a secret they cannot see. Supplying a new value rotates it.
That holds while the endpoint is unchanged. Moving a webhook that HAS a
sealed secret to a different URL without supplying a new one is refused with
400: keeping the sealed secret would let it sign deliveries to a host it
was never issued for, and dropping it would silently un-sign a webhook whose receiver
is still verifying. A webhook with no sealed secret moves freely. To move a signed
one unsigned, delete the destination and declare it again without a secret.
Authorization: admin.platform.alerts.write.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||