Rotate a signing secret
Replace an endpoint's signing secret, with the old one signing alongside for a day.
Returns the endpoint with its new secret, shown only this once. For the next 24 hours, each delivery carries a signature from the old secret and one from the new, so you can switch without dropping a delivery.
Path
idstring RequiredThe webhook endpoint's ID, such aswhk_GFAKLrE8wkBwF4WL.
Errors
- 404
not_foundNo webhook endpoint with that ID belongs to your business. - 403
step_up_requiredThe session hasn't proven its password or a passkey in the last 15 minutes. Confirm it atPOST /sessions/current/step-upand send the request again.
Any request can also fail on its key or its body. See errors.
Request
curl -X POST "https://api.402pay.co/api/v1/webhooks/whk_GFAKLrE8wkBwF4WL/rotate-secret" \
-H "Authorization: Bearer $PAY402_SECRET_KEY"const response = await fetch("https://api.402pay.co/api/v1/webhooks/whk_GFAKLrE8wkBwF4WL/rotate-secret", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAY402_SECRET_KEY}`,
},
});
const { data } = await response.json();import os
import requests
response = requests.post(
"https://api.402pay.co/api/v1/webhooks/whk_GFAKLrE8wkBwF4WL/rotate-secret",
headers={
"Authorization": f"Bearer {os.environ['PAY402_SECRET_KEY']}",
},
)
data = response.json()["data"]Response200 OK
{
"data": {
"id": "whk_GFAKLrE8wkBwF4WL",
"kind": "webhook",
"url": "https://example.com/webhooks/402pay",
"description": "Fulfill orders",
"event_types": ["payment.succeeded", "payment.underpaid", "payment.failed"],
"enabled": true,
"secret_hint": "whsec_••••6NSj",
"created_at": "2026-09-26T21:22:47.012Z",
"updated_at": "2026-09-26T21:23:17.184Z",
"secret": "whsec_zprG6pS4p8qH/nuG5HUwCYHz0OtK6NSj"
}
}