Skip to content
REST API

Rotate a webhook's secret

POST
/webhooks/{webhookId}/rotate

Replaces the signing secret and returns the new one, once. For 24 hours the old secret keeps working: each delivery then carries two signatures in webhook-signature, and a Standard Webhooks library accepts either secret. Send previousSecretExpiresInSeconds (0 to 86400) to shorten that, or 0 to revoke the old secret at once. Rotating again inside the period ends the earlier old secret immediately, and only the newest previous secret is kept. Retries of earlier events are signed the same way.

Required scopes: webhooks:manage

Authorization

AuthorizationBearer <token>

In: header

Path Parameters

webhookId*string

Webhook id, scoped to the key's user.

Match^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
Formatuuid

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/webhooks/497f6eca-6276-4993-bfeb-53cbbbba6f08/rotate" \  -H "Content-Type: application/json" \  -d '{}'
{  "data": {    "id": "4e5f6a7b-8c9d-4e0f-9a1b-2c3d4e5f6a7b",    "secret": "0000000000000000000000000000000000000000000000000000000000000000"  }}