# rotate_site_webhook_secret

Source: https://modulify.ai/docs/mcp/webhooks/rotate-site-webhook-secret

Replaces the signing secret of one webhook with a freshly generated one and returns it.

- Title: Rotate a webhook signing secret
- Scope: `credentials:reveal`
- Access: Destructive

The old secret stops verifying immediately, so every delivery is rejected at the far end until the new secret is pasted in there. Nothing re-syncs this for you. The response carries the new `secret` and the webhook, with its destination as `Host` only.

The tool tells the client to rotate only when a secret has leaked or you explicitly ask, never as routine maintenance, and to hand you the new value straight away. The warnings on `get_site_webhook_secret` apply to the returned value too. See [Webhooks](https://modulify.ai/docs/automations/webhooks#verify-the-signature).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |
| `webhookId` | string | Yes | The webhook id from `list_site_webhooks`. |