# Rotate Webhook Secret

> POST /webhooks/:id/rotate — replace the signing secret for a webhook.

`POST /webhooks/:id/rotate`

Rotates the signing secret for a webhook, invalidating the old secret immediately. Use this if your current secret has been compromised or as part of a regular credential rotation policy. The new plaintext secret is returned **once** in this response — store it securely before the request completes.

**Path parameters**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `id` | string | Yes | The webhook id as returned by [Create Webhook](https://www.sendping.co/docs/api/webhooks-create) or [List Webhooks](https://www.sendping.co/docs/api/webhooks-list) — a numeric string (e.g. `17`), not a UUID. A non-numeric id returns `not_found` (404). |

**Node.js**

```js
import { SendPing } from 'sendping';

const mb = new SendPing('mb_xxxxxxxxx');

const { data, error } = await mb.webhooks.rotate('17');
console.log({ data, error });
```

**Ruby**

```ruby
require "sendping"

SendPing.api_key = "mb_xxxxxxxxx"

SendPing::Webhooks.rotate("17")
```

**PHP**

```php
<?php
require 'vendor/autoload.php';

use SendPing\SendPing;

$sendping = SendPing::client('mb_xxxxxxxxx');

$sendping->webhooks->rotate('17');
```

**Python**

```python
import sendping

sendping.api_key = "mb_xxxxxxxxx"

sendping.Webhooks.rotate("17")
```

**Go**

```go
import "github.com/shekhu10/sendping-sdks/sendping-go"

client := sendping.NewClient("mb_xxxxxxxxx")

rotated, err := client.Webhooks.Rotate("17")
```

**Rust**

```rust
use sendping::SendPing;

let mb = SendPing::new("mb_xxxxxxxxx");

let _rotated = mb.webhooks.rotate("17").await?;
```

**Java**

```java
import co.sendping.SendPing;
import co.sendping.SendPingResponse;

SendPing sendping = new SendPing("mb_xxxxxxxxx");

SendPingResponse response = sendping.webhooks().rotate("17");
```

**.NET**

```csharp
using SendPing;

ISendPing sendping = SendPingClient.Create("mb_xxxxxxxxx");

var resp = await sendping.WebhookRotateAsync("17");
```

**cURL**

```bash
curl -X POST 'https://www.sendping.co/api/webhooks/17/rotate' \
  -H 'Authorization: Bearer mb_xxxxxxxxx'
```

**CLI**

```bash
sendping webhooks rotate 17
```

### Response

```json
{
  "object": "webhook",
  "id": "17",
  "signing_secret": "whsec_xxxxxxxxxx"
}
```

> **Warning:** The new `signing_secret` is only returned here, at rotation. The old secret stops working immediately. Store the new value securely — it cannot be retrieved again.
