# get_site_webhook_secret

Source: https://modulify.ai/docs/api/webhooks/get-site-webhook-secret

Returns the signing secret of one webhook in plain text.

- Title: Reveal a webhook signing secret
- Scope: `credentials:reveal`
- Access: Read only
- Endpoint: `POST /v1/get_site_webhook_secret`

The receiving endpoint uses it to verify that a delivery really came from Modulify, so anyone holding it can forge a delivery that passes verification. It lands wherever the response goes, an AI client's transcript included, which is why it sits behind `credentials:reveal`, a scope that is unticked by default.

The tool tells the client never to print it, put it in a page or a committed file, or send it anywhere you did not ask for, and to reach for it only when you are setting up or repairing the endpoint that receives these calls. See [Webhooks](https://modulify.ai/docs/automations/webhooks#verify-the-signature).

## Request

Call it with a `POST` to `https://api.modulify.ai/v1/get_site_webhook_secret`, sending the inputs below as a JSON object. The token needs the `credentials:reveal` scope.

It only reads and changes nothing, so retrying it is safe.

```bash
curl -X POST https://api.modulify.ai/v1/get_site_webhook_secret \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID","webhookId":"WEBHOOK_ID"}'
```

Over MCP, the same method is the [get_site_webhook_secret tool](https://modulify.ai/docs/mcp/webhooks/get-site-webhook-secret).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |
| `webhookId` | string | Yes | The webhook id from `list_site_webhooks`. |

## Response

Every call answers with the [JSON envelope](https://modulify.ai/docs/api/requests-and-responses#the-response) of `success`, `message`, `data`, `code` and `version`. `data` holds the result described above, and on a method that returns a total, `count` carries it. The [response headers](https://modulify.ai/docs/api/requests-and-responses#headers-on-every-method-call) carry the call's `X-Request-Id` and what is left of your per-minute budget in `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`. [Errors](https://modulify.ai/docs/api/errors) explains every status code a call can answer with.