Skip to content

Add Identity Verification Secret rotation API - #475

Open
thibault-intercom wants to merge 1 commit into
mainfrom
thibault/add-idv-secret-rotation-api-spec
Open

Add Identity Verification Secret rotation API#475
thibault-intercom wants to merge 1 commit into
mainfrom
thibault/add-idv-secret-rotation-api-spec

Conversation

@thibault-intercom

Copy link
Copy Markdown
Contributor

Why?

Moon Active's 2025 security agreement with Intercom calls for self-served rotation of Messenger Identity Verification secrets via API. This spec documents the three new public endpoints that make that possible.

How?

Three endpoints plus supporting schemas and a new `Identity Verification Secrets` tag. The raw HMAC signing material is only returned from `POST /secure_mode_secrets` — list and delete responses contain metadata only. This write-once posture mirrors AWS IAM keys and GitHub fine-grained PATs.

Companion to:

  • intercom/intercom#500245
  • intercom/intercom#500247
  • intercom/intercom#500250
  • intercom/developer-docs (branch `thibault/add-idv-secret-rotation-api-docs`)

Generated with Claude Code

Documents the new public V3 endpoints for self-served rotation of
Messenger Identity Verification secrets:

- GET    /secure_mode_secrets          — list metadata (no signing material)
- POST   /secure_mode_secrets          — create; secret returned ONCE
- DELETE /secure_mode_secrets/{id}     — soft-delete (rotation out)

The create response includes the raw 256-bit HMAC secret; the list and
delete responses do not. This write-once pattern mirrors AWS IAM access
keys and GitHub fine-grained PATs.

Companion to:
- intercom/intercom#500245
- intercom/intercom#500247
- intercom/intercom#500250
@thibault-intercom thibault-intercom self-assigned this Apr 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants