Documents the new public V3 endpoints for self-served rotation of
Messenger Identity Verification secrets:
- GET /secure_mode_secrets — list metadata (no signing material)
- POST /secure_mode_secrets — create; secret returned ONCE
- DELETE /secure_mode_secrets/{id} — soft-delete (rotation out)
The create response includes the raw 256-bit HMAC secret; the list and
delete responses do not. This write-once pattern mirrors AWS IAM access
keys and GitHub fine-grained PATs.
Companion to:
- intercom/intercom#500245
- intercom/intercom#500247
- intercom/intercom#500250
Why?
Moon Active's 2025 security agreement with Intercom calls for self-served rotation of Messenger Identity Verification secrets via API. This spec documents the three new public endpoints that make that possible.
How?
Three endpoints plus supporting schemas and a new `Identity Verification Secrets` tag. The raw HMAC signing material is only returned from `POST /secure_mode_secrets` — list and delete responses contain metadata only. This write-once posture mirrors AWS IAM keys and GitHub fine-grained PATs.
Companion to:
Generated with Claude Code