Reveal a webhook signing secret
get_site_webhook_secret
Returns the signing secret of one webhook in plain text.
The receiving endpoint uses it to verify that a delivery really came from Modulify, so anyone holding it can forge a delivery that passes verification. It lands wherever the response goes, an AI client's transcript included, which is why it sits behind credentials:reveal, a scope that is unticked by default.
The tool tells the client never to print it, put it in a page or a committed file, or send it anywhere you did not ask for, and to reach for it only when you are setting up or repairing the endpoint that receives these calls. See Webhooks.
Request
Call it with a POST to https://api.modulify.ai/v1/get_site_webhook_secret, sending the inputs below as a JSON object. The token needs the credentials:reveal scope.
It only reads and changes nothing, so retrying it is safe.
curl -X POST https://api.modulify.ai/v1/get_site_webhook_secret \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"projectId":"PROJECT_ID","webhookId":"WEBHOOK_ID"}'Over MCP, the same method is the get_site_webhook_secret tool.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |
webhookId |
string | Yes | The webhook id from list_site_webhooks. |
Response
Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.