> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dentalspace.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Documentazione di dentalspace. Il testo completo, incluso il riferimento API, è in /llms-full.txt. Per endpoint, campi e codici di errore la fonte di verità è openapi.json: non usare endpoint o campi non documentati.

# Ruota il segreto di una destinazione

> Scope: `webhooks:write`.



## OpenAPI

````yaml /openapi.json post /webhook-endpoints/{id}/rotate-secret
openapi: 3.1.0
info:
  title: DentalSpace API
  version: 1.0.0
  description: >-
    API pubblica di DentalSpace. Ogni richiesta porta `Authorization: Bearer
    <chiave>`

    (`dsk_live_…`, o `dsk_test_…` per una clinica di prova: nessun messaggio
    parte verso l'esterno).

    La chiave vede solo la sua clinica (e le sue sedi, se limitata): una risorsa
    di altri e' sempre 404.


    Errori: `{ "error": { "code", "message", "details", "requestId" } }`; `code`
    e' stabile, `message` no.

    Limiti: 100 richieste ogni 10 secondi e 20.000 al giorno (UTC) per clinica,
    60 e 12.000 per chiave;

    header `X-RateLimit-*` su ogni risposta, `Retry-After` sul 429 (che non
    consuma).

    Elenchi a cursore: `limit` 1-200, `cursor` = il `nextCursor` precedente,
    `updatedSince` per sincronizzare.

    `Idempotency-Key` sulle creazioni: la stessa chiave entro 24 ore ripete la
    prima risposta.
servers:
  - url: https://api.dentalspace.ai/v1
security:
  - bearerAuth: []
tags:
  - name: Meta
  - name: Studio
  - name: Pazienti
  - name: Agenda
  - name: Preventivi
  - name: Fatture e pagamenti
  - name: Documenti
  - name: Attività
  - name: Contatti commerciali
  - name: Messaggi WhatsApp
  - name: Telefonate
  - name: Agente vocale
  - name: Webhook ed eventi
paths:
  /webhook-endpoints/{id}/rotate-secret:
    post:
      tags:
        - Webhook ed eventi
      summary: Ruota il segreto di una destinazione
      description: 'Scope: `webhooks:write`.'
      operationId: rotateWebhookEndpointSecret
      parameters:
        - name: id
          in: path
          required: true
          description: Identificativo della risorsa.
          schema:
            type: string
            format: uuid
            pattern: >-
              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12})$
      requestBody:
        required: true
        content:
          application/json:
            schema:
              default:
                overlapMinutes: 1440
              type: object
              properties:
                overlapMinutes:
                  description: >-
                    Per quanti minuti si firma anche con il segreto vecchio
                    (0-10080, predefinito 1440 = un giorno).
                  default: 1440
                  type: integer
                  minimum: 0
                  maximum: 10080
      responses:
        '200':
          description: La destinazione, con il segreto nuovo.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebhookEndpointWithSecret'
        '400':
          description: 'Codici: `invalid_request`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: 'Codici: `unauthenticated`, `api_key_invalid`, `api_key_revoked`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: 'Codici: `plan_required`, `insufficient_scope`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: 'Codici: `not_found`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: 'Codici: `conflict`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: 'Codici: `rate_limited`.'
          headers:
            Retry-After:
              $ref: '#/components/headers/Retry-After'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: 'Codici: `internal_error`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: 'Codici: `unavailable`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearerAuth: []
components:
  headers:
    X-Request-Id:
      description: Identificativo della richiesta, da citare all'assistenza.
      schema:
        type: string
    X-RateLimit-Limit:
      description: Il tetto della finestra piu' stretta.
      schema:
        type: integer
    X-RateLimit-Remaining:
      description: Richieste rimaste nella finestra piu' stretta.
      schema:
        type: integer
    X-RateLimit-Reset:
      description: Quando riparte (secondi epoch, UTC).
      schema:
        type: integer
    Retry-After:
      description: Secondi da aspettare prima di riprovare.
      schema:
        type: integer
  schemas:
    WebhookEndpointWithSecret:
      type: object
      properties:
        id:
          type: string
          format: uuid
          pattern: >-
            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12})$
        url:
          type: string
        description:
          anyOf:
            - type: string
            - type: 'null'
        events:
          type: array
          items:
            description: Un tipo di evento del catalogo.
            type: string
            enum:
              - patient.created
              - patient.updated
              - patient.archived
              - appointment.created
              - appointment.rescheduled
              - appointment.confirmed
              - appointment.cancelled
              - appointment.checked_in
              - appointment.completed
              - appointment.no_show
              - treatment_plan.presented
              - treatment_plan.accepted
              - treatment_plan.rejected
              - invoice.issued
              - invoice.paid
              - payment.received
              - installment.overdue
              - lead.created
              - lead.converted
              - task.created
              - task.completed
              - conversation.message_received
              - conversation.handoff_requested
              - call.logged
        enabled:
          type: boolean
        disabledReason:
          description: >-
            too_many_failures: spenta dopo 50 consegne scartate di fila.
            Riaccendila con PATCH enabled=true.
          anyOf:
            - type: string
              enum:
                - manual
                - too_many_failures
            - type: 'null'
        consecutiveFailures:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        previousSecretExpiresAt:
          description: Fino a quest'istante si firma anche con il segreto precedente.
          anyOf:
            - type: string
            - type: 'null'
        secretRotatedAt:
          anyOf:
            - type: string
            - type: 'null'
        createdAt:
          type: string
        updatedAt:
          type: string
        secret:
          description: 'whsec_...: si vede SOLO in questa risposta. Conservalo.'
          type: string
      required:
        - id
        - url
        - description
        - events
        - enabled
        - disabledReason
        - consecutiveFailures
        - previousSecretExpiresAt
        - secretRotatedAt
        - createdAt
        - updatedAt
        - secret
      additionalProperties: false
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              description: Codice stabile, da usare nel codice del client.
              type: string
              enum:
                - invalid_request
                - unauthenticated
                - api_key_invalid
                - api_key_revoked
                - forbidden
                - insufficient_scope
                - organization_suspended
                - plan_required
                - not_found
                - no_availability
                - conflict
                - idempotency_in_progress
                - idempotency_key_reused
                - rate_limited
                - internal_error
                - unavailable
            message:
              description: >-
                Spiegazione per una persona (in italiano). Non confrontarla nel
                codice.
              type: string
            details:
              anyOf:
                - type: object
                  propertyNames:
                    type: string
                  additionalProperties: {}
                - type: 'null'
            requestId:
              description: >-
                Lo stesso valore dell'header X-Request-Id: citalo
                all'assistenza.
              type: string
          required:
            - code
            - message
            - details
            - requestId
          additionalProperties: false
      required:
        - error
      additionalProperties: false
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: dsk_live_… / dsk_test_…

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.