# rotate_site_webhook_secret

Source: https://modulify.ai/docs/api/webhooks/rotate-site-webhook-secret

Replaces the signing secret of one webhook with a freshly generated one and returns it.

- Title: Rotate a webhook signing secret
- Scope: `credentials:reveal`
- Access: Destructive
- Endpoint: `POST /v1/rotate_site_webhook_secret`

The old secret stops verifying immediately, so every delivery is rejected at the far end until the new secret is pasted in there. Nothing re-syncs this for you. The response carries the new `secret` and the webhook, with its destination as `Host` only.

The tool tells the client to rotate only when a secret has leaked or you explicitly ask, never as routine maintenance, and to hand you the new value straight away. The warnings on `get_site_webhook_secret` apply to the returned value too. See [Webhooks](https://modulify.ai/docs/automations/webhooks#verify-the-signature).

## Request

Call it with a `POST` to `https://api.modulify.ai/v1/rotate_site_webhook_secret`, sending the inputs below as a JSON object. The token needs the `credentials:reveal` scope.

> **Warning**
>
> This method is marked destructive: it deletes or overwrites data. Check the inputs before you call it, and send an [Idempotency-Key](https://modulify.ai/docs/api/idempotency) header whenever you might retry it.

```bash
curl -X POST https://api.modulify.ai/v1/rotate_site_webhook_secret \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID","webhookId":"WEBHOOK_ID"}'
```

Over MCP, the same method is the [rotate_site_webhook_secret tool](https://modulify.ai/docs/mcp/webhooks/rotate-site-webhook-secret).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |
| `webhookId` | string | Yes | The webhook id from `list_site_webhooks`. |

## Response

Every call answers with the [JSON envelope](https://modulify.ai/docs/api/requests-and-responses#the-response) of `success`, `message`, `data`, `code` and `version`. `data` holds the result described above, and on a method that returns a total, `count` carries it. The [response headers](https://modulify.ai/docs/api/requests-and-responses#headers-on-every-method-call) carry the call's `X-Request-Id` and what is left of your per-minute budget in `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`. [Errors](https://modulify.ai/docs/api/errors) explains every status code a call can answer with.