---
title: "Rotate a personal webhook signing key"
method: POST
path: "/me/webhooks/{id}/rotate-secret"
tags: ["Webhooks"]
---

# Rotate a personal webhook signing key

`POST /me/webhooks/{id}/rotate-secret`

Optional idempotency key. Reuse the same key only for an identical request; successful responses are replayable for 24 hours.

## Path parameters

- `id` string, required

## Headers

- `Idempotency-Key` string

## Response `200`

The new secret version and one-time signing key.

## Other responses

- `401` — Sign-in required
- `404` — Webhook subscription not found, or not owned by the caller
- `409` — The key is already processing, or was reused with a different request fingerprint.
- `503` — WEBHOOK_HMAC_MASTER not configured, or idempotency storage/response replay is temporarily unavailable

## Changes

- **2026-08-31** `ef21361a36e6` — 2 info
  - added the non-success response with the status `401`
  - added the non-success response with the status `404`
- **2026-08-25** `c3a92b6b6909` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/releases/apis/releases-api/changes/me/webhooks/:id/rotate-secret/post.md)

---

[API](https://skmtc.dev/releases/apis/releases-api.md) · [All operations](https://skmtc.dev/releases/apis/releases-api/llms.txt) · [OpenAPI document](https://skmtc.dev/releases/apis/releases-api/revisions/099eb92e3137?raw)
