REST APIOrganizationWebhook Keys

DEL

Revokes a webhook signing key for an enterprise. This is a soft delete — the key row is preserved for audit purposes but marked as REVOKED.

Revoked keys cannot be used for webhook signature verification. Revocation is irreversible — a new key must be registered to restore access.

Key ID tombstoning: Once a keyId is revoked, it is permanently tombstoned for this enterprise. Attempting to register a new key under the same keyId will return a 400 error, even after revocation. This is intentional security design that prevents key-reuse attacks. Choose a stable, unique keyId from the start (e.g. use a version suffix such as my-key-v2) so that key rotation does not require updating secrets or configuration files that reference the keyId.

Authorization: Caller must be an admin of the specified enterprise.

Path Params

  • enterpriseId string required
    The enterprise ID.
  • keyId string required
    The customer-provided key identifier.

Header Params

  • X-BitGo-OTP string required
    OTP code for verification. Required for webhook key management operations.

Responses

200
Key successfully revoked.

Response Body

object

Response after successfully revoking a webhook signing key.
  • success boolean required
    Whether the revocation was successful.
  • keyId string required
    The customer-provided key identifier that was revoked.
  • revokedAt string date-time required
    When the key was revoked.
  • revokedBy string required
    User who revoked the key.
401
Unauthorized

Response Body

object

  • code string
  • message string
  • status integer
403
Forbidden

Response Body

object

  • code string
  • message string
  • status integer
404
The specified resource was not found

Response Body

object

  • code string
  • message string
  • status integer
409
Conflict - The request conflicts with the current state of the resource

Response Body

object

  • code string
  • message string
  • status integer
500
Server Error - Transient error please try again

Response Body

object

  • code string
  • message string
  • status integer