CustomDomain™ docs
API referenceApplications

Rotate an application's widget client_secret (new secret returned once)

POST
/applications/{id}/client-secret:rotate

Mints a fresh client_secret, stores only its hash, and returns the plaintext exactly once; it is never retrievable again. The old secret stops minting widget tokens (POST /tokens) immediately; already-issued widget JWTs run out their own short TTL. Admin-or-above (keys:manage): a member/viewer API key is rejected with 403.

AuthorizationBearer <token>

Long-lived tenant API key, cd_live_… (production) or cd_test_… (staging, development), stored hashed. Keys created before the switch to cd_ start with sk_live_… / sk_test_… and are still accepted. Scoped to the owning application's tenant.

In: header

Path Parameters

id*string

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/applications/string/client-secret:rotate"
{  "application_id": "string",  "client_secret": "string"}
{  "code": "string",  "title": "string",  "details": "string"}
{  "code": "billing_required",  "title": "An active subscription is needed to connect new domains.",  "details": "This workspace has not started its subscription yet. Domains that are already connected keep working. An owner or admin can set up billing at https://app.customdomain.ai/app/billing."}
{  "code": "string",  "title": "string",  "details": "string"}
{  "code": "string",  "title": "string",  "details": "string"}