Skip to main content
POST
Generates a new HMAC signing secret and returns it once. Use this if a secret leaks, or if you lost the one shown at registration — you do not need to delete and re-register the endpoint.
The previous secret stops working immediately. If your handler rejects requests with an invalid signature, deploy the new secret first, or accept both during the changeover. Deliveries signed with the old secret that your server rejects are retried on the normal 30s / 120s / 480s ladder, so a short gap is recoverable — a long one is not.

Path parameters

string
required
Endpoint UUID from List Webhooks.

Response (200 OK)

string
The new 64-character hex secret. Shown only in this response — subsequent List Webhooks calls return only secret_prefix.
—
The endpoint’s id, url, events, description, payload_version, is_active, and created_at.

Errors

error
No such endpoint, or it belongs to another API key.