---
title: "Generate a webhook signing secret for the authenticated merchant"
method: POST
path: "/api/v1/webhooks/secret"
tags: ["Webhook"]
---

# Generate a webhook signing secret for the authenticated merchant

`POST /api/v1/webhooks/secret`

Generate a webhook signing secret for the authenticated merchant

## Request body

- WebhookSecretInput — Input for webhook secret operations
  - `merchant_id` string, uuid — Merchant ID. Defaults to the logged-in merchant if not provided. Required for admin tokens.

## Response `200`

Success

- WebhookGenerateWebhookSecretResponse
  - `success` boolean, required — Indicates if the request was successful
  - `data` object, required
    - `webhook_secret` string, required — The newly generated webhook signing secret

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden

## Changes

- **2026-06-16** `b372e7d5563d` — 2 breaking, 1 warning, 2 info
  - added required request body
  - the `error/code` response's property type/format changed from `string`/`` to ``/`` for status `400`
  - removed the optional property `error/errors` from the response with the `400` status
  - added the optional property `error/metadata` to the response with the `400` status
  - …1 more
- **2025-11-03** `6637b341d86d` — 1 info
  - endpoint added
- **2025-11-02** `919eb7a392aa` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/banqzinc/apis/quidkey-api/changes/api/v1/webhooks/secret/post.md)

---

[API](https://skmtc.dev/banqzinc/apis/quidkey-api.md) · [All operations](https://skmtc.dev/banqzinc/apis/quidkey-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/banqzinc/quidkey-api/revisions/f86d2bdbcb08/schema)
