CustomDomain™ docs
API referenceApplications

Rotate an application's edge auth secret

POST
/applications/{id}/edge-secret:rotate

Mints a new edge_auth_secret for the application and invalidates the previous one immediately. There is no overlap window, so the edge must be reconfigured with the returned value before it can authenticate again. Requires app:write (member and above); a widget token cannot call it. The secret is returned once and is not retrievable afterwards.

AuthorizationBearer <token>

Long-lived tenant API key, cd_live_… (production) or cd_test_… (staging, development), stored hashed. Keys created before the switch to cd_ start with sk_live_… / sk_test_… and are still accepted. Scoped to the owning application's tenant.

In: header

Path Parameters

id*string

Application id.

Response Body

application/json

application/json

application/json

curl -X POST "https://example.com/applications/string/edge-secret:rotate"
{  "application_id": "string",  "edge_auth_secret": "string"}
{  "code": "string",  "title": "string",  "details": "string"}
{  "code": "string",  "title": "string",  "details": "string"}