> ## Documentation Index
> Fetch the complete documentation index at: https://developers.fastdrop.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate Webhook Secret

> Issue a new signing secret for an endpoint

Generates a new HMAC signing secret and returns it once. Use this if a secret leaks, or if you lost the one shown at registration — you do not need to delete and re-register the endpoint.

<Warning>
  The previous secret stops working **immediately**. If your handler rejects requests with an invalid signature, deploy the new secret first, or accept both during the changeover. Deliveries signed with the old secret that your server rejects are retried on the normal 30s / 120s / 480s ladder, so a short gap is recoverable — a long one is not.
</Warning>

### Path parameters

<ParamField path="webhook_id" type="string" required>
  Endpoint UUID from [List Webhooks](/api-reference/list-webhooks).
</ParamField>

### Response (200 OK)

<ResponseField name="secret" type="string">
  The new 64-character hex secret. Shown only in this response — subsequent
  [List Webhooks](/api-reference/list-webhooks) calls return only `secret_prefix`.
</ResponseField>

<ResponseField name="…" type="—">
  The endpoint's `id`, `url`, `events`, `description`, `payload_version`, `is_active`, and `created_at`.
</ResponseField>

### Errors

<ResponseField name="404 not_found" type="error">
  No such endpoint, or it belongs to another API key.
</ResponseField>

<RequestExample>
  ```bash cURL theme={null}
  curl -X POST \
    https://api.fastdrop.io/api/v1/webhooks/3f9a1c22-8e4b-4d7a-9c11-77d2f0b5a8e3/rotate-secret \
    -H "X-API-Key: fd_live_your_key_here"
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  {
    "id": "3f9a1c22-8e4b-4d7a-9c11-77d2f0b5a8e3",
    "url": "https://your-server.com/webhooks/fastdrop",
    "events": ["job.completed", "job.failed"],
    "description": "Production webhook",
    "secret": "f4e3d2c1b0a9...new_64_char_hex_string",
    "payload_version": "v1",
    "is_active": true,
    "created_at": "2026-08-15T12:00:00Z"
  }
  ```
</ResponseExample>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.