Rotate a webhook signing secret
rotate_site_webhook_secret
Replaces the signing secret of one webhook with a freshly generated one and returns it.
Scopecredentials:revealDestructive
The old secret stops verifying immediately, so every delivery is rejected at the far end until the new secret is pasted in there. Nothing re-syncs this for you. The response carries the new secret and the webhook, with its destination as Host only.
The tool tells the client to rotate only when a secret has leaked or you explicitly ask, never as routine maintenance, and to hand you the new value straight away. The warnings on get_site_webhook_secret apply to the returned value too. See Webhooks.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |
webhookId |
string | Yes | The webhook id from list_site_webhooks. |