Skip to content

feat(webhooks): add signing secret rotation endpoint - #159

Merged
gabrielmfern merged 2 commits into
mainfrom
feat/webhook-signing-secret-rotation
Sep 10, 2026
Merged

gabrielmfern merged 2 commits into
mainfrom
feat/webhook-signing-secret-rotation

Conversation

@gabrielmfern

@gabrielmfern gabrielmfern commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

Adds WebhookRotateSigningSecretAsync(webhookId) for POST /webhooks/{webhook_id}/signing-secret/rotate, spec in resend/resend-openapi#113. The response is the same {object, id, signing_secret} shape create webhook returns, so it reuses WebhookNew instead of adding a type; the mock server and the test follow the same layout as the event replay endpoint (#157). Rollout sub-issue: https://linear.app/resend/issue/DEV-2075

🤖 Generated with Claude Code


Summary by cubic

Adds WebhookRotateSigningSecretAsync(webhookId) to rotate a webhook's signing secret via POST /webhooks/{webhook_id}/signing-secret/rotate, resolving DEV-2075.

  • Reuses the existing WebhookNew response type since the endpoint returns the same shape as webhook creation.
  • Updates the mock server and adds a unit test.
  • Bumps the package version to 0.17.0 and documents the new operation in the README.

Written for commit 94227d4. Summary will update on new commits.

Review in cubic

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 6 files

Confidence score: 4/5

  • In src/Resend/WebhookNew.cs, omitting the rotation response’s object field prevents consumers from reading that response metadata; add the [JsonPropertyName("object")] Object property and populate it in the mock response.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="src/Resend/WebhookNew.cs">

<violation number="1" location="src/Resend/WebhookNew.cs:6">
P2: Consumers cannot access the `object` field from the rotation response. `WebhookNew` exposes only `Id` and `SigningSecret`, so add an `[JsonPropertyName("object")]` `Object` property and populate it in the mock response.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread src/Resend/ResendClient.Webhooks.cs
Comment thread src/Resend/WebhookNew.cs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@gabrielmfern
gabrielmfern merged commit 5db73e5 into main Sep 10, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants