> ## Documentation Index
> Fetch the complete documentation index at: https://omni.fireflo.au/llms.txt
> Use this file to discover all available pages before exploring further.

# POST /v1/webhooks/{endpoint_id}/rotate-secret

> Make a new signing secret for an endpoint.

Makes a new signing secret for an endpoint. Deliveries are signed with it from now on, and the old one stops working at once — update your receiver as you rotate. The answer is the only time the new secret is shown.

<Note>Needs the `webhooks:write` scope.</Note>

## Path parameters

| Field | Type | Required | Notes |
| :- | :- | :- | :- |
| `endpoint_id` | string | Yes | The endpoint's id. |

## Request

<CodeGroup>
  ```bash cURL theme={null}
  curl -X POST https://api.fireflo.au/v1/webhooks/c4e8f2a6-1b3d-4c5e-9f7a-8b6d4e2c0a19/rotate-secret \
    -H "Authorization: Bearer $OMNI_API_KEY"
  ```

  ```python Python theme={null}
  import os

  import requests

  response = requests.post(
      "https://api.fireflo.au/v1/webhooks/c4e8f2a6-1b3d-4c5e-9f7a-8b6d4e2c0a19/rotate-secret",
      headers={"Authorization": f"Bearer {os.environ['OMNI_API_KEY']}"},
  )
  print(response.status_code, response.json())
  ```

  ```javascript Node theme={null}
  const response = await fetch("https://api.fireflo.au/v1/webhooks/c4e8f2a6-1b3d-4c5e-9f7a-8b6d4e2c0a19/rotate-secret", {
    method: "POST",
    headers: {
      Authorization: `Bearer ${process.env.OMNI_API_KEY}`,
    },
  });
  console.log(response.status, await response.json());
  ```
</CodeGroup>

## Response

`200 OK`

```json theme={null}
{
  "id": "c4e8f2a6-1b3d-4c5e-9f7a-8b6d4e2c0a19",
  "secret": "whsec_Qm8tR2vX5kL9pW3yN7cB4hJ1fD6sGa0zUeTiOoYrKxV"
}
```

## Errors

Every refusal is `{"error": {"code", "message", "field"}}`; `field` is there when one input is at fault.

| Status | Error code | When |
| :- | :- | :- |
| 404 | `not_found` | No webhook endpoint has that id on this account. |
| 403 | `scope_missing` | The key doesn't have the `webhooks:write` scope. |

Any request can also be refused for its key, its account or its rate (`key_required`, `invalid_key`, `account_suspended`, `plan_excludes_api`, `address_not_allowed`, `rate_limited`); see [the overview](/api-reference/overview).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.