---
title: "Regenerate a webhook's signing secret (returned once)"
method: POST
path: "/v1/orgs/{orgId}/webhooks/{id}/regenerate-secret"
tags: ["Webhooks"]
---

# Regenerate a webhook's signing secret (returned once)

`POST /v1/orgs/{orgId}/webhooks/{id}/regenerate-secret`

## Path parameters

- `orgId` string, required
- `id` string, required

## Response `200`

Regenerated

- WebhookSecret
  - `id` string, required
  - `secret` string, required
  - `secretPrefix` string, required

## Other responses

- `401` — Missing or invalid API key
- `403` — The caller is authenticated but may not do this. The caller's role or the API key's scope does not allow it, or the request targets another organization (FORBIDDEN, or NOT_A_MEMBER for a session), or the organization is suspended pending review (ORG_SUSPENDED) or has been deleted (ORG_DISABLED). A new API key or a wider scope clears neither of the last two; see [Account and balance refusals](https://docs.openrelay.inc/docs/errors#account-and-balance-refusals). A user session whose email address is not confirmed is refused on every operation (EMAIL_UNVERIFIED); confirm the address from the confirmation email, then sign in again.
- `404` — Resource not found

---

[API](https://skmtc.dev/openrelay/apis/openrelay-api.md) · [All operations](https://skmtc.dev/openrelay/apis/openrelay-api/llms.txt) · [OpenAPI document](https://skmtc.dev/openrelay/apis/openrelay-api/revisions/1eb2b3fc2024?raw)
