Rotate a webhook endpoint secret
rotate_webhook_secretRotate a webhook endpoint's signing secret when a credential leaks or expires. Requires confirm=true; the new secret is saved to a private local file, not returned.
Instructions
Rotate a webhook endpoint secret. May affect delivery, audience membership, published data or irreversible state. Requires confirm=true. Webhook response secrets are redacted; new signing secrets are saved only to a private local file.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| force | No | Rotating again while a previous rotation's overlap window is still open returns `409` (see the responses below). Pass `true` to rotate anyway, immediately expiring the older secret. | |
| account | No | Named private account from KIT_ACCOUNTS. Defaults to KIT_DEFAULT_ACCOUNT or the first configured account. | |
| confirm | No | Must be true for audience/delivery changes, publishing, destructive operations and signing-secret changes. Use only for an action requested by the user. | |
| payload | No | Complete JSON body instead of individual body flags. Supports nullable fields and nested bulk structures. Cannot be combined with body flags or payload_file. | |
| secret_name | Yes | New private filename under KIT_PRIVATE_DIR. Required before creating/rotating a signing secret; never overwritten. | |
| payload_file | No | Local JSON request body file, at most 5 MB. Contents are validated before the API call and are never logged. | |
| webhook_endpoint_id | Yes | Positive webhook endpoint id. |