> ## Documentation Index
> Fetch the complete documentation index at: https://www.tryleap.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Leap's API is at https://api.tryleap.ai. Send the key in the x-api-key header or as Authorization: Bearer; keys start with leap_.
> Take model IDs and input schemas from GET /v1/models/{creator}/{name}, or from https://api.tryleap.ai/v1/public/models without a key. Never guess an input field: unknown fields are a 400.
> Model inputs take uploaded file IDs (file_...), never URLs.
> To give a coding agent the whole API, install the Leap skill: curl -fsSL https://www.tryleap.ai/install.sh | sh
> The full OpenAPI 3.1 spec is at https://www.tryleap.ai/docs/openapi.json.

# Retrieve the default webhook secret

> The secret that signs events sent to the `webhook` URL a generation or batch request names. It's made the first time you read it. Keep it in your server's environment.

Needs an API key with the `generations:write` scope.



## OpenAPI

````yaml /openapi.json get /v1/webhooks/default/secret
openapi: 3.1.0
info:
  title: Leap API
  version: 1.0.0
  description: >-
    One API for the best image, video and audio models. Every request goes to
    `https://api.tryleap.ai` with your API key in the `x-api-key` header, or as
    `Authorization: Bearer leap_...`. Create a key at
    https://app.tryleap.ai/go/api.


    Guides, examples and the errors list are at https://www.tryleap.ai/docs.
servers:
  - url: https://api.tryleap.ai
security:
  - ApiKey: []
  - Bearer: []
tags:
  - name: Models
    description: >-
      Every model and preset you can run, with its price and the JSON Schema of
      the input it takes.
  - name: Quotes
    description: >-
      The exact price of a run before you start it, with its input checked and
      its defaults filled in.
  - name: Generations
    description: >-
      A generation is one run of a model or preset: queued, then running, then
      succeeded, failed or canceled. Only a succeeded run is charged.
  - name: Batches
    description: >-
      Up to 50 generations priced and held together in one request, each then
      run as its own generation.
  - name: Webhooks
    description: >-
      URLs your workspace's events are POSTed to, signed following Standard
      Webhooks, and the default secret for the `webhook` URL a request names.
  - name: Events
    description: >-
      What happened in your workspace, kept 30 days, with each delivery to your
      webhooks and a way to send one again.
  - name: Files
    description: >-
      Photos, videos and sounds that models take as input. Upload one, then pass
      its `file_...` ID in the input field the model's schema names.
  - name: Credits
    description: Your workspace's balance in US dollars.
externalDocs:
  url: https://www.tryleap.ai/docs
paths:
  /v1/webhooks/default/secret:
    get:
      tags:
        - Webhooks
      summary: Retrieve the default webhook secret
      description: >-
        The secret that signs events sent to the `webhook` URL a generation or
        batch request names. It's made the first time you read it. Keep it in
        your server's environment.


        Needs an API key with the `generations:write` scope.
      operationId: retrieveDefaultWebhookSecret
      parameters: []
      responses:
        '200':
          description: The secret.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Limit:
              $ref: '#/components/headers/RateLimit-Limit'
            RateLimit-Remaining:
              $ref: '#/components/headers/RateLimit-Remaining'
            RateLimit-Reset:
              $ref: '#/components/headers/RateLimit-Reset'
          content:
            application/json:
              example:
                object: webhook_secret
                secret: whsec_DMlar1QHs8wCiHFLVgS15l9Crm0IK7kUDXDPN1lNDrg=
              schema:
                $ref: '#/components/schemas/WebhookSecret'
        '400':
          $ref: '#/components/responses/ConflictingCredentials'
        '401':
          $ref: '#/components/responses/AuthenticationRequired'
        '403':
          $ref: '#/components/responses/PermissionDenied'
        '429':
          $ref: '#/components/responses/RateLimitExceeded'
components:
  headers:
    X-Request-Id:
      required: true
      description: >-
        This request's ID. Include it when you contact support; it's also
        `request_id` in an error.
      schema:
        type: string
        description: >-
          This request's ID. Include it when you contact support; it's also
          `request_id` in an error.
        example: req_01J9Z8Q4N2K7T5V3X6Y8B0C1D2
    RateLimit-Limit:
      required: true
      description: Requests allowed per window from your client.
      schema:
        type: integer
        minimum: 0
        maximum: 9007199254740991
        description: Requests allowed per window from your client.
        example: 300
    RateLimit-Remaining:
      required: true
      description: Requests left in the current window.
      schema:
        type: integer
        minimum: 0
        maximum: 9007199254740991
        description: Requests left in the current window.
        example: 299
    RateLimit-Reset:
      required: true
      description: Seconds until the window resets.
      schema:
        type: integer
        minimum: 0
        maximum: 9007199254740991
        description: Seconds until the window resets.
        example: 42
    Retry-After:
      required: true
      description: Seconds to wait before you retry.
      schema:
        type: integer
        minimum: 0
        maximum: 9007199254740991
        description: Seconds to wait before you retry.
        example: 42
  schemas:
    WebhookSecret:
      type: object
      properties:
        object:
          type: string
          const: webhook_secret
        secret:
          type: string
          description: >-
            The signing secret, whsec_ and base64. Keep it in your server's
            environment.
      required:
        - object
        - secret
      additionalProperties: false
      description: The secret that signs events sent to the webhook URL a request names.
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - invalid_request_error
                - rate_limit_error
                - authentication_error
                - permission_error
                - conflict_error
                - billing_error
                - api_error
              description: >-
                The kind of error. Branch on `type` and `code`, never on
                `message`.
            code:
              type: string
              enum:
                - invalid_parameter
                - invalid_request
                - conflicting_credentials
                - placeholder_in_path
                - method_not_allowed
                - payload_too_large
                - unsupported_media_type
                - ip_rate_limit_exceeded
                - authentication_required
                - missing_api_key
                - invalid_api_key
                - permission_denied
                - not_found
                - resource_not_found
                - gone
                - conflict
                - rate_limit_exceeded
                - insufficient_credit
                - service_unavailable
                - internal_error
              description: >-
                A stable code for this error. Each one is explained at
                https://www.tryleap.ai/docs/errors.
            message:
              type: string
              description: >-
                What went wrong, written for a person. It can change; don't
                parse it.
            param:
              description: >-
                For a `400`, the field at fault, such as `input.prompt`;
                otherwise null.
              type:
                - string
                - 'null'
            doc_url:
              description: A page that explains this error, when there is one.
              type:
                - string
                - 'null'
            request_id:
              type: string
              description: >-
                This request's ID, as in the `X-Request-Id` header. Include it
                when you contact support.
          required:
            - type
            - code
            - message
            - param
            - doc_url
            - request_id
          additionalProperties: false
      required:
        - error
      additionalProperties: false
  responses:
    ConflictingCredentials:
      description: '`conflicting_credentials`'
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimit-Limit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimit-Remaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            conflicting_credentials:
              value:
                error:
                  type: invalid_request_error
                  code: conflicting_credentials
                  message: Send one API key.
                  param: null
                  doc_url: null
                  request_id: req_8kQ2vX9mR4tL6nB1cW3yZ5aD
    AuthenticationRequired:
      description: '`authentication_required`'
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimit-Limit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimit-Remaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            authentication_required:
              value:
                error:
                  type: authentication_error
                  code: authentication_required
                  message: Authentication is required.
                  param: null
                  doc_url: null
                  request_id: req_8kQ2vX9mR4tL6nB1cW3yZ5aD
    PermissionDenied:
      description: '`permission_denied`'
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimit-Limit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimit-Remaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            permission_denied:
              value:
                error:
                  type: permission_error
                  code: permission_denied
                  message: Permission denied.
                  param: null
                  doc_url: null
                  request_id: req_8kQ2vX9mR4tL6nB1cW3yZ5aD
    RateLimitExceeded:
      description: '`rate_limit_exceeded`'
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimit-Limit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimit-Remaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimit-Reset'
        Retry-After:
          $ref: '#/components/headers/Retry-After'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            rate_limit_exceeded:
              value:
                error:
                  type: rate_limit_error
                  code: rate_limit_exceeded
                  message: Too Many Requests
                  param: null
                  doc_url: null
                  request_id: req_8kQ2vX9mR4tL6nB1cW3yZ5aD
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Your workspace API key, `leap_...`. Create one at
        https://app.tryleap.ai/go/api, and keep it on your server.
    Bearer:
      type: http
      scheme: bearer
      description: >-
        The same API key as `Authorization: Bearer leap_...`, the way most HTTP
        clients and coding agents send one. Send one header or the other; two
        different keys are a `400`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.