Skip to main content
POST
Rotate Webhook Secret

Authorizations

Authorization
string
header
required

Send an account API key in the Authorization: Bearer <key> header.

Headers

OpenPMM-Request-Id
string

Optional request ID. OpenPMM returns this value when it is valid. Otherwise, OpenPMM creates a request ID.

Maximum string length: 128
Idempotency-Key
string
required

A unique key for this operation. Use the same key when you retry the same request. Different input with the same key returns 409.

Required string length: 1 - 200

Path Parameters

workspace_id
string
required

Unique workspace ID.

Example:

"ws_01JABCDEF"

endpoint_id
string
required

Unique webhook endpoint ID.

Example:

"wh_01JABCDEF"

Response

The new secret and the previous-secret expiry time.

secret
string
required
read-only

New signing secret. This value is returned only once.

previous_secret_expires_at
string<date-time>
required
Example:

"2026-08-09T12:00:00.000Z"