Modulify

Rotate a webhook signing secret

rotate_site_webhook_secret

Replaces the signing secret of one webhook with a freshly generated one and returns it.

POST /v1/rotate_site_webhook_secretScopecredentials:revealDestructive

The old secret stops verifying immediately, so every delivery is rejected at the far end until the new secret is pasted in there. Nothing re-syncs this for you. The response carries the new secret and the webhook, with its destination as Host only.

The tool tells the client to rotate only when a secret has leaked or you explicitly ask, never as routine maintenance, and to hand you the new value straight away. The warnings on get_site_webhook_secret apply to the returned value too. See Webhooks.

Request

Call it with a POST to https://api.modulify.ai/v1/rotate_site_webhook_secret, sending the inputs below as a JSON object. The token needs the credentials:reveal scope.

This method is marked destructive: it deletes or overwrites data. Check the inputs before you call it, and send an Idempotency-Key header whenever you might retry it.

curl -X POST https://api.modulify.ai/v1/rotate_site_webhook_secret \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID","webhookId":"WEBHOOK_ID"}'

Over MCP, the same method is the rotate_site_webhook_secret tool.

Inputs

Input Type Required Description
projectId string Yes The site id.
webhookId string Yes The webhook id from list_site_webhooks.

Response

Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.