API referenceApplications
Rotate an application's widget client_secret (new secret returned once)
Mints a fresh client_secret, stores only its hash, and returns the plaintext exactly once; it is never retrievable again. The old secret stops minting widget tokens (POST /tokens) immediately; already-issued widget JWTs run out their own short TTL. Admin-or-above (keys:manage): a member/viewer API key is rejected with 403.
AuthorizationBearer <token>
Long-lived tenant API key, cd_live_… (production) or cd_test_… (staging, development), stored hashed. Keys created before the switch to cd_ start with sk_live_… / sk_test_… and are still accepted. Scoped to the owning application's tenant.
In: header
Path Parameters
id*string
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/applications/string/client-secret:rotate"{ "application_id": "string", "client_secret": "string"}{ "code": "string", "title": "string", "details": "string"}{ "code": "billing_required", "title": "An active subscription is needed to connect new domains.", "details": "This workspace has not started its subscription yet. Domains that are already connected keep working. An owner or admin can set up billing at https://app.customdomain.ai/app/billing."}{ "code": "string", "title": "string", "details": "string"}{ "code": "string", "title": "string", "details": "string"}