> For the complete index of the 402pay docs, see [llms.txt](https://developer.402pay.co/llms.txt).

# Rotate a signing secret

Replace an endpoint's signing secret, with the old one signing alongside for a day.

`POST https://dash.402pay.co/api/v1/webhooks/{id}/rotate-secret`

Returns the endpoint with its new `secret`, shown only this once. For the next 24 hours, each delivery carries a signature from the old secret and one from the new, so you can switch without dropping a delivery.

### Path

- `id` (string, required): The webhook endpoint's ID, such as `whk_GFAKLrE8wkBwF4WL`.

### Errors

- 404 `not_found` No webhook endpoint with that ID belongs to your business.
- 403 `step_up_required` The session hasn't proven its password or a passkey in the last 15 minutes. Confirm it at `POST /sessions/current/step-up` and send the request again.

Any request can also fail on its key or its body. See [errors](https://developer.402pay.co/api/errors.md).

Request, cURL:

```bash
curl -X POST "https://dash.402pay.co/api/v1/webhooks/whk_GFAKLrE8wkBwF4WL/rotate-secret" \
  -H "Authorization: Bearer $PAY402_SECRET_KEY"
```

Request, Node.js:

```js
const response = await fetch("https://dash.402pay.co/api/v1/webhooks/whk_GFAKLrE8wkBwF4WL/rotate-secret", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.PAY402_SECRET_KEY}`,
  },
});
const { data } = await response.json();
```

Request, Python:

```python
import os

import requests

response = requests.post(
    "https://dash.402pay.co/api/v1/webhooks/whk_GFAKLrE8wkBwF4WL/rotate-secret",
    headers={
        "Authorization": f"Bearer {os.environ['PAY402_SECRET_KEY']}",
    },
)
data = response.json()["data"]
```

Response, 200 OK:

```json
{
  "data": {
    "id": "whk_GFAKLrE8wkBwF4WL",
    "kind": "webhook",
    "url": "https://example.com/webhooks/402pay",
    "description": "Fulfill orders",
    "event_types": ["payment.succeeded", "payment.underpaid", "payment.failed"],
    "enabled": true,
    "secret_hint": "whsec_••••6NSj",
    "created_at": "2026-09-26T21:22:47.012Z",
    "updated_at": "2026-09-26T21:23:17.184Z",
    "secret": "whsec_zprG6pS4p8qH/nuG5HUwCYHz0OtK6NSj"
  }
}
```
