# get_site_webhook_secret

Source: https://modulify.ai/docs/mcp/webhooks/get-site-webhook-secret

Returns the signing secret of one webhook in plain text.

- Title: Reveal a webhook signing secret
- Scope: `credentials:reveal`
- Access: Read only

The receiving endpoint uses it to verify that a delivery really came from Modulify, so anyone holding it can forge a delivery that passes verification. It lands wherever the response goes, an AI client's transcript included, which is why it sits behind `credentials:reveal`, a scope that is unticked by default.

The tool tells the client never to print it, put it in a page or a committed file, or send it anywhere you did not ask for, and to reach for it only when you are setting up or repairing the endpoint that receives these calls. See [Webhooks](https://modulify.ai/docs/automations/webhooks#verify-the-signature).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |
| `webhookId` | string | Yes | The webhook id from `list_site_webhooks`. |