Rotate secret
const url = 'https://api.wink.travel/api/managing-entity/d5b8a3c2-9e6f-4a1b-8d34-7c2e1f0a5b69/webhook/b7e4c1a2-3f5d-4e8a-9c21-6f0b5d8e3a47/rotate-secret';const options = { method: 'POST', headers: {'Wink-Version': '2.0', Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.wink.travel/api/managing-entity/d5b8a3c2-9e6f-4a1b-8d34-7c2e1f0a5b69/webhook/b7e4c1a2-3f5d-4e8a-9c21-6f0b5d8e3a47/rotate-secret \ --header 'Authorization: Bearer <token>' \ --header 'Wink-Version: 2.0'Generates a new signing secret. The previous secret keeps verifying deliveries for 24 hours so you can roll your servers; both signatures are present in Wink-Signature during that window.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Identifier of the managing entity that owns the webhook
Example
d5b8a3c2-9e6f-4a1b-8d34-7c2e1f0a5b69Unique webhook identifier
Example
b7e4c1a2-3f5d-4e8a-9c21-6f0b5d8e3a47Header Parameters
Section titled “Header Parameters”Responses
Section titled “Responses”New secret (shown once)
Returned exactly once, on create and on secret rotation: the webhook and its plaintext signing secret. Store the secret now — it cannot be retrieved later.
object
Plaintext signing secret (whsec_…). Shown once.
Lightweight projection of a webhook subscription that delivers HTTP POST notifications to a configured endpoint whenever subscribed events occur on the Wink platform.
object
Datetime this record was first created
Whether this webhook is actively subscribed to events.
HTTPS endpoint URL to POST events to.
Unique identifier for this record.
Datetime this record was last updated
Descriptive name of this webhook, e.g. ‘Booking confirmation sync’ or ‘Payment notifications’.
Unique managing entity (owner) identifier
Display name of the managing entity that owns this webhook.
Until when the previous secret is still accepted after a rotation.
Last four characters of the signing secret. The secret itself is returned only once, on create and rotate.
Unique authenticated user identifier
Optimistic-locking version. Echo this value back as an If-Match request header on a conditional update; the server responds 409 if the record changed in the meantime. Null when this projection has no backing versioned document, in which case no conditional update is possible.
Example
{ "secret": "whsec_dGVzdC1zZWNyZXQtdmFsdWUtZm9yLWRvY3M", "webhook": { "createdDate": "2026-01-14T09:30:00", "enabled": true, "eventList": [ "booking.created" ], "eventUrl": "https://api.example.com/webhooks/wink/events", "id": "b7e4c1a2-3f5d-4e8a-9c21-6f0b5d8e3a47", "lastUpdate": "2026-02-03T16:45:12", "name": "Booking confirmation sync", "ownerIdentifier": "d5b8a3c2-9e6f-4a1b-8d34-7c2e1f0a5b69", "ownerName": "The Siam Residences, Bangkok", "userIdentifier": "c3a9f2e1-8b4d-4c7a-a1e2-5f0b6d9e2c84", "version": 3 }}Bad Request — missing or invalid request parameter or body
object
object
Example
Unauthorized — authentication is required or the session has expired
object
object
Example
Forbidden — authenticated but lacking the required permission or scope
object
object
Example
Not Found — the requested resource does not exist
object
object
Example
Method Not Allowed — the HTTP verb is not supported on this endpoint
object
object
Example
Conflict — the resource was modified by someone else since you read it; re-read it and retry with the new version
object
object
Example
Unsupported Media Type — use application/json
object
object
Example
Internal Server Error — an unexpected failure occurred on the server
object
object
Example
Service Unavailable — a downstream dependency is unreachable
