SendlySendly
API ReferenceWebhooks

Rotate a webhook signing secret

POST
/api/v1/webhooks/{id}/rotate-secret

Mint a fresh signing secret. The new plaintext is returned EXACTLY ONCE, here — no endpoint reads it back, so a secret you lose is replaced by rotating again rather than recovered.

Rotation overlaps on purpose. The outgoing secret keeps verifying until previous_secret_expires_at, and every delivery inside that window carries BOTH signatures in the webhook-signature header — so you can deploy the new secret to your verifier whenever you like without dropping an in-flight event. Rotating twice inside the window discards the older secret: only one previous secret is ever live.

url, event_types and status are unchanged.

Requires the webhooks:write scope — Create, edit, and delete your webhook endpoints.

Authorization

AuthorizationBearer <token>

API key authentication. Use a sk_* (FULL) or pk_* (SENDING_ONLY) key as the bearer token. Public keys (pk_*) are restricted to the email-send endpoints and the self-serve list subscribe/unsubscribe pair; every other endpoint — event tracking included — answers 403 for them. In scope terms (used by /api/v1/* operations): FULL keys hold every scope; SENDING_ONLY keys hold only emails:send.

In: header

Path Parameters

id*string

Resource id.

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X POST "https://example.com/api/v1/webhooks/497f6eca-6276-4993-bfeb-53cbbbba6f08/rotate-secret"
{
  "secret": "string",
  "previous_secret_expires_at": "2019-08-24T14:15:22Z"
}
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "code": "string",
  "request_id": "string",
  "errors": [
    {
      "pointer": "string",
      "code": "string",
      "message": "string"
    }
  ]
}
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "code": "string",
  "request_id": "string",
  "errors": [
    {
      "pointer": "string",
      "code": "string",
      "message": "string"
    }
  ]
}
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "code": "string",
  "request_id": "string",
  "errors": [
    {
      "pointer": "string",
      "code": "string",
      "message": "string"
    }
  ]
}
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "code": "string",
  "request_id": "string",
  "errors": [
    {
      "pointer": "string",
      "code": "string",
      "message": "string"
    }
  ]
}
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "code": "string",
  "request_id": "string",
  "errors": [
    {
      "pointer": "string",
      "code": "string",
      "message": "string"
    }
  ]
}
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "code": "string",
  "request_id": "string",
  "errors": [
    {
      "pointer": "string",
      "code": "string",
      "message": "string"
    }
  ]
}