Rotate a webhook endpoint's secret
POST/v1/webhook-endpoints/{endpointId}/rotate-secret
Issues a new signing secret, returned ONCE. For the next 24 hours deliveries carry two signatures — the new secret's and the old one's — so the receiver can switch without dropping an event.
Permissions: any valid key · Kind: write · Cost: 2 units
Cannot be undone.
Path parameters
| Field | Type | Required | Description |
|---|---|---|---|
endpointId |
uuid | yes |
Body
None.
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
object |
"webhook_endpoint_secret" | yes | |
endpointId |
uuid | yes | |
secret |
string | yes | The new signing secret. Shown ONLY in this response. |
previousSecretExpiresAt |
string | null | yes | Until then deliveries carry two signatures, one per secret. |
Errors
Errors are problem details. Besides the refusals described above, any call like this one can return:
invalid_request— Invalid requestunauthorized— Missing or invalid API keyinsufficient_scope— Missing permissionrate_limited— Rate limit reachednot_found— Not foundidempotency_key_reused— Idempotency-Key reusedrequest_in_progress— Request in progress