Skip to documentation

API · Webhooks

Rotate Signing Secret

Generate and retrieve a new webhook signing secret (requires full access). Deliveries are signed with both the new and immediately preceding secrets for 24 hours.

POST/webhooks/{webhook_id}/signing-secret/rotateFull access

Request parameters

ParameterTypeDescription
webhook_id
path · required
stringThe Webhook ID.
Idempotency-Key
header · optional
string
1–256 characters
Makes the request safe to retry. See Idempotency.

Request example

Set OPENSEND_BASE_URL=https://api.example.com and OPENSEND_API_KEY=os_replace_me on your server.

bash
curl -X POST "$OPENSEND_BASE_URL/webhooks/YOUR_webhook_id/signing-secret/rotate" \
  -H "Authorization: Bearer $OPENSEND_API_KEY"

Response

200 · application/json. Example IDs stand for IDs returned by your installation.

json
{
  "object": "webhook",
  "id": "479e3145-dd38-476b-932c-529ceb705947",
  "signing_secret": "whsec_..."
}

Behavior and errors

Save the new signing_secret and update your receiver within 24 hours. During that window attempts include signatures from the new and immediately preceding secret. Rotating again replaces the preceding key.

Use a full-access credential. Unknown or foreign resources return 404. See authentication, errors, rate limits, and pagination.