Rotate a webhook signing secret
rotate_site_webhook_secret
Replaces the signing secret of one webhook with a freshly generated one and returns it.
The old secret stops verifying immediately, so every delivery is rejected at the far end until the new secret is pasted in there. Nothing re-syncs this for you. The response carries the new secret and the webhook, with its destination as Host only.
The tool tells the client to rotate only when a secret has leaked or you explicitly ask, never as routine maintenance, and to hand you the new value straight away. The warnings on get_site_webhook_secret apply to the returned value too. See Webhooks.
Request
Call it with a POST to https://api.modulify.ai/v1/rotate_site_webhook_secret, sending the inputs below as a JSON object. The token needs the credentials:reveal scope.
This method is marked destructive: it deletes or overwrites data. Check the inputs before you call it, and send an Idempotency-Key header whenever you might retry it.
curl -X POST https://api.modulify.ai/v1/rotate_site_webhook_secret \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"projectId":"PROJECT_ID","webhookId":"WEBHOOK_ID"}'Over MCP, the same method is the rotate_site_webhook_secret tool.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |
webhookId |
string | Yes | The webhook id from list_site_webhooks. |
Response
Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.