Update a webhook endpoint
Changes url, subscribed_events, or is_active, or rotates the secret. Every field is optional, but the body must carry at least one; an empty object is 400 VALIDATION_ERROR. Concurrent PUTs are last write wins: every field you send is written, so a body built from a stale GET can undo another caller’s change and still answer 200.
Every call needs webhooks:manage. Changing url or subscribed_events, or setting is_active to true, also needs reservations:read; a value sent back unchanged is not a change. Pausing (is_active: false) and rotating need webhooks:manage alone, so you can always stop a stream or replace a leaked secret; a 403 names the fields that asked for more.
rotate_secret: true returns the new secret in full exactly once. New deliveries are signed with it at once, but one already picked up keeps the old secret for up to 90 seconds, so accept both briefly. Rotation is not idempotent and Idempotency-Key is ignored: a retried rotate rotates again and the first secret is gone. Pausing and repointing have delivery side effects of their own; see Managing endpoints in the Reservations guide.
Authentication
API key generated in the Autolane Portal. Keys are organization-scoped, carry granular permissions, and are environment-specific: a sandbox key only works against the sandbox host, and a production key only against the production host.