/v1/webhooks/endpoints/{endpoint_id}/rotate-secretbetaRotate the signing secret
- Needs
- Manage webhook endpoints
(webhooks:write) - Plan
- Any plan with API access
- Limits
- 60 a minute per key
- Dry run
- Yes — every check runs with ?dry_run=true, nothing changes
- Confirm
- Header
Api-Confirm: rotate - Undo
- Cannot be undone after 24 hours. Before then, both secrets work.
Makes a new signing secret, shown only in this response. The old one keeps working for 24 hours (deliveries carry both signatures), then stops. Switch your receiver to the new one in time.
Try it
Protects against doing it twice if you retry: a retry with the same key gets the first answer back instead of running again.
Code and response
curl -X POST 'https://mcp.wa-api.cloud/v1/webhooks/endpoints/ep_01J8Z6Q4M9W2X7K3B5N1R0T8YA/rotate-secret?dry_run=true' \ -H "Authorization: Bearer $API_KEY" \ -H "Idempotency-Key: $(uuidgen)"
The code reads your key from $API_KEY.
Parameters
| Field | Type | What it is |
|---|---|---|
| endpoint_idrequired | string · path | The endpoint id.pattern ^ep_[0-9A-HJKMNP-TV-Z]{26}$Signed in? Pick one from your data with “My data”. |
Headers
| Field | Type | What it is |
|---|---|---|
| Authorizationrequired | header | Bearer $API_KEY — your API key. |
| Api-Version | header | The API version to use, e.g. 2026-10-01. Default: the version your key is pinned to.one of: 2026-10-01 · pattern ^\d{4}-\d{2}-\d{2}$ |
| Idempotency-Keyrequired | header | Required here. Any unique string (8–128 characters), e.g. your order id plus the step. Kept 24 hours. Not needed with dry_run=true.pattern ^[A-Za-z0-9._:-]+$ · 8–128 characters |
| Api-Confirmrequired | header | Type the operation's verb (e.g. delete, submit) to confirm a change that cannot be undone or that WhatsApp or your customers see. Not needed with dry_run=true. |
Response 200
The new secret (once).
| Field | Type | What it is |
|---|---|---|
| endpointrequired | object | |
| idrequired | string | |
| urlrequired | string | |
| descriptionrequired | string or null | |
| statusrequired | string | active | disabled | paused |
| custom_headersrequired | object | Custom header names; values masked to the last 4 characters. |
| consecutive_failuresrequired | number | |
| disabled_atrequired | string or null | |
| disabled_reasonrequired | string or null | |
| signing_secretrequired | string | Always masked. The secret is shown once, on create or rotate. |
| payload_formatrequired | string | "data" = the event's data object as the body; "envelope" = {id, type, version, api_version, occurred_at, company_id, data}.one of: data, envelope |
| created_atrequired | string or null | |
| updated_atrequired | string or null | |
| subscriptions | object or null | |
| countrequired | number | |
| all_activerequired | boolean | |
| event_typesrequired | array of object | |
| signing_secretrequired | string | |
| old_secret_valid_untilrequired | string | |
| warningrequired | string | |
| dry_run | boolean | true when this was a dry run: every check ran and nothing changed. |
Errors
Errors are application/problem+json. Branch on code.
| Status | Code | When |
|---|---|---|
| 400 | invalid_input | A field is missing or has the wrong format. |
| 401 | unauthenticated | The Authorization header is missing, the key is unknown, expired or revoked. |
| 403 | entitlement_required | The workspace's plan does not include API access ( |
| 403 | insufficient_scope | The key does not have the permission this operation needs. |
| 404 | not_found | No endpoint with this id. |
| 409 | conflict | Also returned while a request with the same Idempotency-Key is still running. |
| 428 | confirm_required | Send the header |
| 429 | rate_limited | The key or workspace went over its rate limit. Wait for |
| 503 | upstream_unavailable | A service behind the API is briefly unavailable. Safe to retry with backoff. |
| 504 | timeout | The change did not finish in time. Retry with the same Idempotency-Key: it never runs twice. |
Examples
Rotate after a leak
Response 200
{
"endpoint": {
"id": "ep_01J8Z6Q4M9W2X7K3B5N1R0T8YA",
"url": "https://hooks.example.com/incoming",
"description": "Order system",
"status": "active",
"custom_headers": {
"X-Hook-Token": "••••9f2a"
},
"payload_format": "envelope",
"consecutive_failures": 0,
"disabled_reason": null,
"signing_secret": "whsec_••••••••",
"created_at": "2026-09-10T12:00:00Z",
"updated_at": "2026-09-10T12:00:00Z",
"disabled_at": null
},
"signing_secret": "whsec_EXAMPLE_not_a_real_secret_111111111111",
"old_secret_valid_until": "2026-09-25T10:00:00Z",
"warning": "Store this secret now. It will not be shown again."
}Operation path
The same operation is also at POST /v1/ops/webhooks_rotate_secret, with every field in the JSON body.