API referenceApplications
Rotate an application's edge auth secret
Mints a new edge_auth_secret for the application and invalidates the previous one immediately. There is no overlap window, so the edge must be reconfigured with the returned value before it can authenticate again. Requires app:write (member and above); a widget token cannot call it. The secret is returned once and is not retrievable afterwards.
Authorization
apiKey AuthorizationBearer <token>
Long-lived tenant API key, cd_live_… (production) or cd_test_… (staging, development), stored hashed. Keys created before the switch to cd_ start with sk_live_… / sk_test_… and are still accepted. Scoped to the owning application's tenant.
In: header
Path Parameters
id*string
Application id.
Response Body
application/json
application/json
application/json
curl -X POST "https://example.com/applications/string/edge-secret:rotate"{ "application_id": "string", "edge_auth_secret": "string"}{ "code": "string", "title": "string", "details": "string"}{ "code": "string", "title": "string", "details": "string"}