Rotate a webhook signing secret
Mint a fresh signing secret. The new plaintext is returned EXACTLY ONCE, here — no endpoint reads it back, so a secret you lose is replaced by rotating again rather than recovered.
Rotation overlaps on purpose. The outgoing secret keeps verifying until previous_secret_expires_at, and every delivery inside that window carries BOTH signatures in the webhook-signature header — so you can deploy the new secret to your verifier whenever you like without dropping an in-flight event. Rotating twice inside the window discards the older secret: only one previous secret is ever live.
url, event_types and status are unchanged.
Requires the webhooks:write scope — Create, edit, and delete your webhook endpoints.
API key authentication. Use a sk_* (FULL) or pk_* (SENDING_ONLY) key as the bearer token. Public keys (pk_*) are restricted to the email-send endpoints and the self-serve list subscribe/unsubscribe pair; every other endpoint — event tracking included — answers 403 for them. In scope terms (used by /api/v1/* operations): FULL keys hold every scope; SENDING_ONLY keys hold only emails:send.
In: header
Path Parameters
Resource id.
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X POST "https://example.com/api/v1/webhooks/497f6eca-6276-4993-bfeb-53cbbbba6f08/rotate-secret"{
"secret": "string",
"previous_secret_expires_at": "2019-08-24T14:15:22Z"
}{
"type": "http://example.com",
"title": "string",
"status": 0,
"detail": "string",
"instance": "string",
"code": "string",
"request_id": "string",
"errors": [
{
"pointer": "string",
"code": "string",
"message": "string"
}
]
}{
"type": "http://example.com",
"title": "string",
"status": 0,
"detail": "string",
"instance": "string",
"code": "string",
"request_id": "string",
"errors": [
{
"pointer": "string",
"code": "string",
"message": "string"
}
]
}{
"type": "http://example.com",
"title": "string",
"status": 0,
"detail": "string",
"instance": "string",
"code": "string",
"request_id": "string",
"errors": [
{
"pointer": "string",
"code": "string",
"message": "string"
}
]
}{
"type": "http://example.com",
"title": "string",
"status": 0,
"detail": "string",
"instance": "string",
"code": "string",
"request_id": "string",
"errors": [
{
"pointer": "string",
"code": "string",
"message": "string"
}
]
}{
"type": "http://example.com",
"title": "string",
"status": 0,
"detail": "string",
"instance": "string",
"code": "string",
"request_id": "string",
"errors": [
{
"pointer": "string",
"code": "string",
"message": "string"
}
]
}{
"type": "http://example.com",
"title": "string",
"status": 0,
"detail": "string",
"instance": "string",
"code": "string",
"request_id": "string",
"errors": [
{
"pointer": "string",
"code": "string",
"message": "string"
}
]
}