# Set or generate a signing secret

`PUT https://evohub.io/api/v1/integrations/{id}/signing-secret`

Part of the [On-Call API](https://docs-dev.evohub.io/oncall.md) reference · operationId `setIntegrationSigningSecret`.

For `github`, `gitlab`, `jenkins` and `sonarqube` integrations: the secret
the tool signs its deliveries with, so EvoHub can reject anything not signed
with it.

Send `{"secret": "…"}` to store a secret already set in the tool (16–256
printable characters without spaces, at least 8 of them different). Send an
empty body or an empty `secret` to have one generated: it is returned once, in
`signing_secret`, with `Cache-Control: no-store`, and never again. Either way
the previous secret stops working at once. A secret you sent is not echoed.

**Permission (API-key scope):** `oncall:integration:write`.

## Authorization

Any one of:

- `bearerAuth` (oncall:integration:write)
- `apiKeyHeader` (oncall:integration:write)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Path parameters

- `id` (string, required, example `int_6e5d4c3b-2a19-4f8e-b7d6-c5b4a3928170`): The integration's id.

## Request body

Content type: `application/json`

Type: `object`

- `secret` (string): The secret to store; empty or omitted to generate one.

## Responses

### 200 — The secret is set.

Content type: `application/json`

Type: `object`

- `data` (SigningSecretResult, required)
  - `signing_secret_configured` (boolean)
  - `generated` (boolean)
  - `signing_secret` (string): Only when generated, and only in this response.
- `success` (boolean, required, value `true`)

### 400 — The body is not JSON (`INVALID_BODY`); the integration's type has no signing secret (`VALIDATION_FAILED`, field `type`); or the secret is not acceptable (`VALIDATION_FAILED`, field `secret`).

Content type: `application/json`

Type: `ValidationError`

- `error` (object, required)
  - `code` (string, required, value `VALIDATION_FAILED`)
  - `message` (string, required)
  - `details` (array of object, required)
    - `field` (string)
    - `message` (string)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 403 — The key lacks the scope this endpoint needs (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 404 — No such integration in your organization or your teams (`INTEGRATION_NOT_FOUND`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 409 — Signing secrets are not available on this server (`SIGNING_SECRET_UNAVAILABLE`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

## Example request

```bash
curl -X PUT 'https://evohub.io/api/v1/integrations/int_6e5d4c3b-2a19-4f8e-b7d6-c5b4a3928170/signing-secret' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer <TOKEN>' \
  -d '{}'
```
