---
title: "Rotate webhook signing secret"
method: POST
path: "/webhooks/{webhookId}/rotate-secret"
tags: ["Webhooks"]
---

# Rotate webhook signing secret

`POST /webhooks/{webhookId}/rotate-secret`

Rotate the webhook signing secret. The new secret is returned only once.

## Path parameters

- `webhookId` string, required — Webhook ID (whk_*).

## Headers

- `Idempotency-Key` string, required
- `X-Instance-ID` string, nullable

## Request body

- object
  - `data` object, required
    - `attributes` object, required
      - `expiresInSeconds` integer, required — Grace period in seconds for the previous secret (0 = immediate cutover, max 86400).

## Response `200`

Successful Response

- object
  - `data` object, required
    - `type` 'webhook', required — Resource type. Always `webhook`.
    - `id` string, required — Webhook ID (whk_*).
    - `attributes` object, required
      - `signingSecret` string, required — New webhook signing secret. Returned only once.
      - `previousSecretExpiresAt` string, date-time, nullable, required — RFC 3339 timestamp when the previous secret expires, or null for immediate cutover.
    - `relationships` object, required
      - `party` object, required — Party that owns the webhook.
        - `data` object, required — Related resource identifier.
          - `type` 'party', required — Resource type. Always `party`.
          - `id` string, required

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found. Returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error. The response contains one error object for each invalid request value.
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

## Changes

- **2026-09-02** `c7c12da5915f` — 12 info
  - added the optional property `errors/items/meta/limitScope` to the response with the `400` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `401` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `403` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `404` status
  - …8 more
- **2026-08-27** `359d267dca88` — 1 info
  - deleted the `header` request parameter `X-Agent-ID` with deprecation
- **2026-08-23** `b1ad79e918ac` — 1 info
  - `header` request parameter `X-Agent-ID` was deprecated
- **2026-08-08** `0bb9c54b1f61` — 1 breaking
  - added the pattern `^whk_[0-9a-f]{32}$` to the `path` request parameter `webhookId`
- **2026-07-26** `270e233e401c` — 2 warning
  - for the `header` request parameter `Idempotency-Key`, the maxLength was set to `255`
  - for the `path` request parameter `webhookId`, the maxLength was set to `64`

[Change history](https://skmtc.dev/natural/apis/natural-api/changes/webhooks/:webhookId/rotate-secret/post.md)

---

[API](https://skmtc.dev/natural/apis/natural-api.md) · [All operations](https://skmtc.dev/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc.dev/natural/apis/natural-api/revisions/b61b8441fba4?raw)
