Skip to main content
POST
Rotate the signing secret

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

id
string
required

Webhook ID

Response

Secret rotated

id
string
required
object
enum<string>
required
Available options:
webhook
createdAt
string
required
url
string
required
topics
string[]
required
enabled
boolean
required
description
string | null
required
consecutiveFailures
integer
required

Consecutive failed delivery attempts (circuit-breaker streak; any success resets).

Required range: -9007199254740991 <= x <= 9007199254740991
cooldownUntil
string | null
required

While in the future, deliveries to this endpoint are held and sent after the window (cooldown).

autoDisabledAt
string | null
required

Set when the system disabled the endpoint after sustained delivery failure.

secret
string

HMAC signing secret (whsec_...). Present only for tokens holding webhook:manage, and only on single-object reads, create, and rotate. An EMPTY string means the stored secret can no longer be decrypted (e.g. the encryption key changed) — call rotate-secret to mint a fresh one.