Renouveler votre secret de signature
curl --request POST \
--url https://guichet.apidjonanko.tech/v1/merchants/me/webhook-secret/rotate \
--header 'x-api-key: <api-key>' \
--header 'x-api-secret: <api-key>'const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'x-api-secret': '<api-key>'}
};
fetch('https://guichet.apidjonanko.tech/v1/merchants/me/webhook-secret/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://guichet.apidjonanko.tech/v1/merchants/me/webhook-secret/rotate"
headers = {
"x-api-key": "<api-key>",
"x-api-secret": "<api-key>"
}
response = requests.post(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://guichet.apidjonanko.tech/v1/merchants/me/webhook-secret/rotate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>",
"x-api-secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"webhookSecret": "whsec_…",
"notice": "<string>"
}{
"success": false,
"error": {
"code": "INVALID_CREDENTIALS",
"message": "Identifiants API invalides."
},
"requestId": "9f1c2b7e-4a5d-4c8f-b0a1-e2d3c4b5a697",
"timestamp": "2026-10-01T10:12:04.000Z"
}Notifications
Renouveler votre secret de signature
Coupure immédiate. Les notifications sont signées avec le nouveau secret dès cet appel ; l’ancien n’est plus valable. Déployez le nouveau sans délai, sinon vos vérifications de signature échoueront.
POST
/
merchants
/
me
/
webhook-secret
/
rotate
Renouveler votre secret de signature
curl --request POST \
--url https://guichet.apidjonanko.tech/v1/merchants/me/webhook-secret/rotate \
--header 'x-api-key: <api-key>' \
--header 'x-api-secret: <api-key>'const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'x-api-secret': '<api-key>'}
};
fetch('https://guichet.apidjonanko.tech/v1/merchants/me/webhook-secret/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://guichet.apidjonanko.tech/v1/merchants/me/webhook-secret/rotate"
headers = {
"x-api-key": "<api-key>",
"x-api-secret": "<api-key>"
}
response = requests.post(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://guichet.apidjonanko.tech/v1/merchants/me/webhook-secret/rotate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>",
"x-api-secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"webhookSecret": "whsec_…",
"notice": "<string>"
}{
"success": false,
"error": {
"code": "INVALID_CREDENTIALS",
"message": "Identifiants API invalides."
},
"requestId": "9f1c2b7e-4a5d-4c8f-b0a1-e2d3c4b5a697",
"timestamp": "2026-10-01T10:12:04.000Z"
}Coupure immédiate. Les notifications sont signées avec le nouveau secret dès cet appel ; l’ancien n’est plus accepté. Déployez-le sans délai, sinon toutes vos vérifications de signature échoueront.Si vous ne pouvez pas déployer instantanément, faites accepter les deux secrets par votre code pendant la fenêtre de bascule.
Authorizations
Votre clé publique, préfixée gk_live_ (ou gk_test_).
Votre secret, préfixé gs_live_ (ou gs_test_). Affiché une seule fois, à l'émission de la clé. Il ne doit jamais quitter vos serveurs.
