API · Webhooks
Rotate Signing Secret
Generate and retrieve a new webhook signing secret (requires full access). Deliveries are signed with both the new and immediately preceding secrets for 24 hours.
POST
/webhooks/{webhook_id}/signing-secret/rotateFull accessRequest parameters
| Parameter | Type | Description |
|---|---|---|
webhook_idpath · required | string | The Webhook ID. |
Idempotency-Keyheader · optional | string1–256 characters | Makes the request safe to retry. See Idempotency. |
Request example
Set OPENSEND_BASE_URL=https://api.example.com and OPENSEND_API_KEY=os_replace_me on your server.
bash
curl -X POST "$OPENSEND_BASE_URL/webhooks/YOUR_webhook_id/signing-secret/rotate" \
-H "Authorization: Bearer $OPENSEND_API_KEY"Response
200 · application/json. Example IDs stand for IDs returned by your installation.
json
{
"object": "webhook",
"id": "479e3145-dd38-476b-932c-529ceb705947",
"signing_secret": "whsec_..."
}Behavior and errors
Save the new signing_secret and update your receiver within 24 hours. During that window attempts include signatures from the new and immediately preceding secret. Rotating again replaces the preceding key.
Use a full-access credential. Unknown or foreign resources return 404. See authentication, errors, rate limits, and pagination.