> ## Documentation Index
> Fetch the complete documentation index at: https://docs.engini.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Set default destination

> Creates the default destination if the account has none, and otherwise re-points the
existing default at the new URL.
            
A SIGNING SECRET IS RETURNED ONLY WHEN THIS CALL CREATES THE DESTINATION. Repeating the call
to re-point an existing default returns the destination WITHOUT a secret, and that is deliberate,
not an omission: minting a fresh secret on every re-point would silently invalidate the receiver
the customer already has verifying signatures. Call rotate-secret when a new secret is what you
actually want. This is what keeps "the secret is returned exactly once" literally true.



## OpenAPI

````yaml /api-reference/openapi.json put /v1/triggers/destination
openapi: 3.0.0
info:
  title: Engini DeveloperAPI
  version: v1
  description: 'Merged public developer API spec: Identity + WorkflowApi.'
servers:
  - url: https://api.engini.io
security:
  - Bearer: []
  - ApiKey: []
tags:
  - name: Auth
    description: Identify the caller a Developer API request is authenticated as.
  - name: Applications
    description: >-
      Discover the applications (toolkits) available in Engini and their
      connection requirements.
  - name: Tools
    description: Browse and execute the tools exposed by Engini applications.
  - name: Toolsets
    description: Manage toolsets - named groupings of connections and tools.
  - name: McpServers
    description: >-
      Inspect and maintain MCP servers - the account-wide endpoints that expose
      Engini tools and workflows over the Model Context Protocol. Distinct from
      the MCPClient connection kind, which is Engini consuming a third-party MCP
      server.
  - name: Connections
    description: >-
      Manage connections to applications, including OAuth sign-in and
      default-connection selection.
  - name: Triggers
    description: >-
      Create triggers that fire when something changes in a connected app, and
      manage the destinations their events are delivered to.
paths:
  /v1/triggers/destination:
    put:
      tags:
        - Triggers
      summary: Set default destination
      description: >-
        Creates the default destination if the account has none, and otherwise
        re-points the

        existing default at the new URL.
                    
        A SIGNING SECRET IS RETURNED ONLY WHEN THIS CALL CREATES THE
        DESTINATION. Repeating the call

        to re-point an existing default returns the destination WITHOUT a
        secret, and that is deliberate,

        not an omission: minting a fresh secret on every re-point would silently
        invalidate the receiver

        the customer already has verifying signatures. Call rotate-secret when a
        new secret is what you

        actually want. This is what keeps "the secret is returned exactly once"
        literally true.
      operationId: Triggers_PutDefaultDestination
      parameters: []
      requestBody:
        x-name: request
        description: The url to point the default destination at.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PutDefaultDestinationRequest'
        required: true
        x-position: 1
      responses:
        '200':
          description: >-
            The destination. A signing secret is included only when this call
            created it (201); a re-point

            returns the destination alone (200).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TriggerDestinationView'
        '201':
          description: >-
            The destination. A signing secret is included only when this call
            created it (201); a re-point

            returns the destination alone (200).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TriggerDestinationCreated'
        '400':
          description: Bad request - malformed body or invalid parameters.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized - missing or invalid bearer token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: Forbidden - the caller lacks access to the resource.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: Not found - the resource does not exist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '429':
          description: Too many requests - rate limit exceeded.
          headers:
            Retry-After:
              description: Number of seconds to wait before retrying.
              schema:
                type: integer
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal server error - an unexpected error occurred.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - Bearer: []
        - ApiKey: []
components:
  schemas:
    PutDefaultDestinationRequest:
      type: object
      description: PUT /v1/triggers/destination - the single-destination convenience alias.
      additionalProperties: false
      properties:
        url:
          type: string
          description: An https URL on a publicly routable host.
          nullable: true
        name:
          type: string
          description: >-
            Name for the destination if this call CREATES it. Ignored when
            re-pointing an existing default -

            renaming is not what this endpoint is for. Defaults to "default".
          nullable: true
        max_consecutive_failures:
          type: integer
          format: int32
          nullable: true
    TriggerDestinationView:
      type: object
      description: >-
        A named HTTP endpoint Engini delivers trigger events to. The signing
        secret is never included
         here - it is shown once, when the destination is created or its secret is rotated.
      additionalProperties: false
      required:
        - id
        - name
        - url
        - status
      properties:
        id:
          type: integer
          description: >-
            The numeric id, which is what POST /v1/triggers's destination_id
            takes. Routes

            address destinations by Name; this is here so a caller can bind a
            trigger to one

            without a second lookup.
          format: int32
        name:
          type: string
          description: Slug, unique per account among live destinations.
        url:
          type: string
        is_default:
          type: boolean
          description: >-
            True on the one destination that receives events from triggers
            naming no destination.
        status:
          $ref: '#/components/schemas/TriggerDestinationStatusDTO'
        consecutive_failures:
          type: integer
          description: >-
            Consecutive DEAD-LETTERED events, not failed attempts. Reset to zero
            by any successful delivery

            and by re-enabling the destination.
          format: int32
        max_consecutive_failures:
          type: integer
          description: How many consecutive dead-letters auto-disable this endpoint.
          format: int32
        last_delivery_at:
          type: string
          format: date-time
          nullable: true
        last_failure_at:
          type: string
          format: date-time
          nullable: true
        last_failure:
          type: string
          description: >-
            Why the last delivery failed, sanitised for a tenant to read - a
            status code and reason, never a

            stack trace or an internal host.
          nullable: true
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
          nullable: true
    TriggerDestinationCreated:
      type: object
      description: >-
        The response to the three calls that MINT a secret: create,
        rotate-secret, and

        PUT /v1/triggers/destination when that call creates the account default.
      additionalProperties: false
      required:
        - destination
      properties:
        destination:
          description: The destination itself - identical to what every read path returns.
          oneOf:
            - $ref: '#/components/schemas/TriggerDestinationView'
        signing_secret:
          type: string
          description: >-
            The plaintext esec_… HMAC-SHA256 signing secret. Store it now; it is
            never shown again.
    ErrorResponse:
      type: object
      description: >-
        Unified error envelope for every non-200 response from
        /api/DeveloperAPI/v1/*.

        See applications-tools-spec.md §"Error envelope".
      additionalProperties: false
      required:
        - errorCode
        - message
        - requestId
        - timestamp
        - path
      properties:
        errorCode:
          type: string
          description: Machine-readable error code identifying the failure.
        message:
          type: string
          description: Human-readable error message.
        requestId:
          type: string
          description: Identifier of the request, for support/correlation.
        timestamp:
          type: string
          description: Timestamp when the error occurred (ISO 8601).
        path:
          type: string
          description: Request path that produced the error.
        details:
          type: array
          description: Per-field validation details, when applicable.
          nullable: true
          items:
            $ref: '#/components/schemas/ErrorDetail'
    TriggerDestinationStatusDTO:
      type: string
      description: >-
        Whether a destination is currently accepting deliveries. Engini disables
        one automatically after
         too many consecutive failures; updating the destination enables it again.
      x-enumNames:
        - Active
        - AutoDisabled
      enum:
        - active
        - auto_disabled
    ErrorDetail:
      type: object
      description: A single field-level error detail within an ErrorResponse.
      additionalProperties: false
      required:
        - field
        - issue
      properties:
        field:
          type: string
          description: Name of the field the issue relates to.
        issue:
          type: string
          description: Description of the issue with the field.
  securitySchemes:
    Bearer:
      type: http
      description: Enter your JWT token
      scheme: bearer
      bearerFormat: JWT
    ApiKey:
      type: apiKey
      description: >-
        Opaque Developer API key (prefix `eng_`). Authenticates as the key's
        owner and resolves the account automatically.
      name: x-api-key
      in: header

````