---
title: "Rotate Webhook Endpoint Secret"
method: POST
path: "/v2/webhooks/endpoints/{endpoint_id}/rotate-secret"
tags: ["webhooks"]
---

# Rotate Webhook Endpoint Secret

`POST /v2/webhooks/endpoints/{endpoint_id}/rotate-secret`

Create a new signing secret for an endpoint. The new secret is returned only in this response.

For the next 24 hours every request carries two signatures, one with the old secret and one with the new, so the receiver keeps verifying whichever secret it holds. Deploy the new secret within that window.

## Path parameters

- `endpoint_id` string, required

## Response `200`

Successful Response

- WebhookSecretRotated
  - `endpoint_id` string, required
  - `secret` string, required — The new signing secret (`whsec_...`). Returned only in this response.
  - `previous_secret_valid_for_hours` integer, required — How long requests stay signed with the old secret as well (24).

## Other responses

- `401` — Missing or invalid API key.
- `403` — The connection is read-only and cannot change webhooks (MCP connections without write access).
- `404` — `Webhook endpoint not found.` The id does not exist, or belongs to another organization.
- `429` — `Too many webhook management requests. Try again shortly.` Retry after the `Retry-After` header.
- `503` — Webhooks are temporarily unavailable. Retry shortly.

## Changes

- **2026-09-24** `61a9364ad042` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/runcaptain/apis/api-reference/changes/v2/webhooks/endpoints/:endpoint_id/rotate-secret/post.md)

---

[API](https://skmtc.dev/runcaptain/apis/api-reference.md) · [All operations](https://skmtc.dev/runcaptain/apis/api-reference/llms.txt) · [OpenAPI document](https://skmtc.dev/runcaptain/apis/api-reference/revisions/ac61e472bb7d?raw)
