Skip to main content
POST
Confirm your deployment before running this request. This page describes an API contract; a published reference does not establish hosted availability. Check the dated host report and obtain your deployment URL and credentials. Replace the example host if your provisioned service uses a different URL.
Issue a new signing secret for an existing webhook endpoint. Mirrors POST /keys/{id}/rotate: row identity (id, url, events, is_active, created_at) is preserved; only the secret changes. updated_at advances. The new plaintext secret is returned in full exactly once — read it before the response goes out the door, because subsequent reads omit it. The old secret stops working the instant this commits. Tenants should orchestrate the cutover the same way as API keys: deploy the new secret to the receiver before calling this, OR tolerate a brief window of failed-signature deliveries. Delivery history (success / failure / retry rows) is unchanged — rotation deliberately preserves it so audit trails survive. Inactive endpoints 409 (parallel to API key rotate). Cross-tenant ids 404. Same scope (admin) as the rest of the webhook surface.

Path parameters

string (uuid)
required

Request body

No request body.

Response

WebhookEndpointWithSecret
string
required
string
required
string[]
required
boolean
required
string
required
string
required
string
required
HMAC-SHA256 signing secret. Compare incoming X-Webhook-Signature against HMAC(secret, f'{t}.{body}').

Status codes

Using this contract

Read the source OpenAPI document for declared schemas and alternatives. This page also includes documented corrections from the spec overlays. Example IDs and values are illustrative; replace them with records from your workspace.
Last modified on September 21, 2026