Create or update the Demo Launches webhook
Saves one callback per workspace. Use an HTTPS URL in production. The plaintext HMAC secret is returned only when the endpoint is first created or when rotateSecret is true. To pause an existing endpoint without resubmitting its URL, send enabled: false and an empty url.
Authorizations
Personal API token, sent as Authorization: Bearer <SANDYWP_API_KEY>. Obtain one from the dashboard account menu (API keys), sandywp auth login, or POST /api/account/tokens. A missing or invalid token returns 401 auth_required. Scoped OAuth tokens are limited to the Imports family and GET /api/account/me; see the top-level conventions.
Headers
Selects which of the caller's workspaces to act in, for accounts belonging to more than one (legacy alias: X-SandyWP-Organization). Defaults to the caller's own personal workspace when omitted. Every id in this API (sandboxes, Templates, repositories) is scoped to a single workspace, so this header changes which set of resources is visible.
Body
Callback URL. May be empty only when disabling an existing endpoint.
2048"https://hooks.example.com/sandywp/demo-ready"
Whether new demo.ready deliveries should be queued.
Replace the signing secret and return the new value once.

