webhooks

Rotate Webhook Endpoint Secret

Create a new signing secret for an endpoint. The new secret is returned only in this response.

For the next 24 hours every request carries two signatures, one with the old secret and one with the new, so the receiver keeps verifying whichever secret it holds. Deploy the new secret within that window.

post/v2/webhooks/endpoints/{endpoint_id}/rotate-secret

Path parameters

endpoint_idstring required

The endpoint's id (whe_...).

Response

Successful Response

endpoint_idstring required
secretstring required

The new signing secret (whsec_...). Returned only in this response.

previous_secret_valid_for_hoursinteger required

How long requests stay signed with the old secret as well (24).

Changes

Changed in 1 of the 13 revisions of this API.1