Developers
API referenceWebhook endpoints

Roll the signing secret

POST
/webhook-endpoints/{id}/roll-secret

Generates a new signing secret and returns it once. The old secret keeps working for 24 hours, so you can switch without missing events.

Scope: webhooks:manage.

Authorization

bearerAuth
AuthorizationBearer <token>

A Platform API token, wyc_live_... or wyc_test_..., created at Settings > API tokens in the dashboard.

In: header

Path Parameters

id*string

Id of the webhook endpoint.

Match^whe_[A-Za-z0-9]{24}$

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/webhook-endpoints/string/roll-secret"
{  "id": "whe_2xL7rCkZa8bW1vT9yN6pDmQ3",  "object": "webhook_endpoint",  "livemode": true,  "url": "https://example.com/webhooks/woodyoucare",  "description": "CRM sync",  "events": [    "allocation.created",    "allocation.planted",    "verification.published"  ],  "include_personal_data": false,  "status": "enabled",  "disabled_reason": null,  "secret": "whsec_9f2c...",  "created_at": "2026-09-28T09:00:00Z",  "updated_at": "2026-09-28T09:00:00Z"}