API reference: no example reads as a real secret
The webhook examples carried a made-up signing secret in g1t's whsec_ format, which GitHub's secret scanning flagged as a Stripe webhook secret (alert #1). It was never a real secret: g1t seals webhook secrets and never returns them after creation. Examples now write whsec_… as the others do, and a test fails on any example that reads as a real credential.
No changes
This commit changes no files.