1. Webchat Identity Verification
  • Getting Started
    • Introduction
    • Quickstart
    • Authentication
    • Status codes
  • Webhook
    • Webhook Setup
    • Webhook Events and Schema
  • SDKs
    • @klink.cloud/call-sdk
  • API Reference
    • Contact
      • Listing
      • Create
      • Filter By SocialPlatformId
      • Form Fields
      • Detail
      • Update
      • Delete
      • Fetch Contact Groups
      • Update tags
      • Filter By Phone Number
    • Tag
      • Listing
    • Channel
      • Listing
      • Create
    • Ticket
      • Listing
      • Create
      • Filter by Contact ID
      • Form Fields
      • Update
      • Update status
    • Category
      • Listing
    • CxLog
      • Listing
    • Message
      • Send message
      • Create comments
      • Get Comments
    • Media Manager
      • Upload File (multipart)
      • Get Folders
      • Get Folder By ID
      • Create Folder
      • Update Folder
      • Delete Folder
      • Get Files
      • Get File By ID
      • Create File
      • Update File
      • Delete File
    • Agent Activity
      • Get Agents Activities
    • Telephony
      • Get Telephony CDR
    • User
      • Create
      • Listing
      • Detail
      • Update
      • Delete
    • Automation Queue
      • Create
      • Listing
      • Detail
      • Update
      • Delete
      • Add Member
      • Remove Member
    • Role
      • Listing
    • Webchat Identity Verification
      • Get identity verification settings
        GET
      • Update identity verification settings
        PUT
      • Create or rotate the identity secret
        POST
    • Schemas
      • RequestId
      • IdentityVerificationStatus
      • IdentityVerificationUpdate
      • IdentityVerificationSettings
      • IdentitySecret
      • userToken (JWT claims)
      • Error
Blog
Github
  1. Webchat Identity Verification

Create or rotate the identity secret

POST
/api/v1/webchat/channels/{channelId}/identity-verification/secret
Creates the channel's identity secret, or replaces it if one exists.
The secret is returned only in this response. Store it in your server's
secret manager. Never put it in a website, mobile app or source code.
Rotating takes effect immediately:
every userToken and userHash made with the old secret stops working;
every active chat session ends, and the user continues as a guest until your
page or app provides a new token.
Deploy the new secret to your servers at the same time.

Request

Authorization
Bearer Token
Provide your bearer token in the
Authorization
header when making requests to protected resources.
Example:
Authorization: Bearer ********************
or
Path Params

Responses

🟢201
application/json
New secret created.
Bodyapplication/json

🟠400BadRequest
🟠401Unauthorized
🟠404ChannelNotFound
🟠429TooManyRequests
🔴502BadGateway
Request Request Example
Shell
JavaScript
Java
Swift
curl --location --request POST 'https://apigw.klinkcx.com/api/v1/webchat/channels//identity-verification/secret' \
--header 'Authorization: Bearer <token>'
Response Response Example
201 - Success
{
    "requestId": "9a1e3b5c-7d2f-4c8a-b6e4-0f1d2c3b4a59",
    "secret": "9f2c4a7e1b3d5f60a8c2e4b6d8f0a1c3e5b7d9f1a3c5e7b9d1f3a5c7e9b1d3f5"
}
Modified at 2026-09-29 08:27:56
Previous
Update identity verification settings
Next
RequestId
Built with