Retrieve an endpoint signing secret
curl --request GET \
--url https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret")
.header("X-API-Key", "<api-key>")
.asString();using RestSharp;
var options = new RestClientOptions("https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret");
var client = new RestClient(options);
var request = new RestRequest("");
request.AddHeader("X-API-Key", "<api-key>");
var response = await client.GetAsync(request);
Console.WriteLine("{0}", response.Content);
{
"signing_secret": "whsec_dGVzdF9zaWduaW5nX3NlY3JldA=="
}{
"error": {
"code": "INVALID_DESCRIPTION",
"message": "description must be 255 characters or fewer.",
"correlation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
}{
"error": {
"code": "INVALID_DESCRIPTION",
"message": "description must be 255 characters or fewer.",
"correlation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
}{
"error": {
"code": "INVALID_DESCRIPTION",
"message": "description must be 255 characters or fewer.",
"correlation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
}{
"error": {
"code": "INVALID_DESCRIPTION",
"message": "description must be 255 characters or fewer.",
"correlation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
}{
"error": {
"code": "INVALID_DESCRIPTION",
"message": "description must be 255 characters or fewer.",
"correlation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
}Payment Webhooks
Retrieve Signing Secret
Retrieve the endpoint-specific signing secret
GET
/
v1
/
webhook_endpoints
/
{id}
/
signing_secret
Retrieve an endpoint signing secret
curl --request GET \
--url https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret")
.header("X-API-Key", "<api-key>")
.asString();using RestSharp;
var options = new RestClientOptions("https://api.sbx.moduluslabs.io/v1/webhook_endpoints/{id}/signing_secret");
var client = new RestClient(options);
var request = new RestRequest("");
request.AddHeader("X-API-Key", "<api-key>");
var response = await client.GetAsync(request);
Console.WriteLine("{0}", response.Content);
{
"signing_secret": "whsec_dGVzdF9zaWduaW5nX3NlY3JldA=="
}{
"error": {
"code": "INVALID_DESCRIPTION",
"message": "description must be 255 characters or fewer.",
"correlation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
}{
"error": {
"code": "INVALID_DESCRIPTION",
"message": "description must be 255 characters or fewer.",
"correlation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
}{
"error": {
"code": "INVALID_DESCRIPTION",
"message": "description must be 255 characters or fewer.",
"correlation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
}{
"error": {
"code": "INVALID_DESCRIPTION",
"message": "description must be 255 characters or fewer.",
"correlation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
}{
"error": {
"code": "INVALID_DESCRIPTION",
"message": "description must be 255 characters or fewer.",
"correlation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
}Store the secret in a server-side secret manager. Never expose it in browser code,
application logs, source control, or ordinary endpoint configuration.
Use this secret with a maintained Standard Webhooks verification library and
the exact raw request body.
Authorizations
A Modulus API key with the required webhook scope.
Path Parameters
Webhook endpoint identifier returned by the create operation.
Response
Signing secret retrieved.
Endpoint-specific secret used to verify Standard Webhooks signatures.
Pattern:
^whsec_Example:
"whsec_dGVzdF9zaWduaW5nX3NlY3JldA=="
Was this page helpful?