Rotate a webhook signing secret

POST/webhooks/{webhook_id}/secret-rotations

Generates a new signing secret for the webhook endpoint.

The previous secret remains valid for overlap_hours (24 hours by default, up to 72). During this period, each delivery carries one signature per active secret.

The new secret is returned only once. Retrying the request with the same Idempotency-Key does not return the secret again.

AuthorizationBearer <token>

Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.

In: header

Path Parameters

webhook_id*string

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/webhooks/string/secret-rotations" \  -H "Content-Type: application/json" \  -d '{}'
{  "data": {    "object": "webhook_secret_rotation",    "previous_secret_expires_at": "2019-08-24T14:15:22Z",    "secret": "string"  }}