Skip to content
API reference

Rotate webhook secret

Mint a new signing secret with a 24h grace window where both keys remain valid.

POST/api/v1/webhooks/{id}/rotate-secret
Step-by-step guideStep 1 of 3

Select a stage to see what happens.

Your integration
Request readyIllustrative example
POST/webhooks/{id}/rotate-secret
Authorization
Bearer ••••••••
Accept
application/json

Prepare the request

Use credentials for the selected environment and complete the required parameters.

Illustrative flow · no data is sent

How this endpoint works

Rotate the HMAC signing key. The new secret is returned ONCE; the old one stays valid for 24 hours so you can deploy the new key to your handler without dropping deliveries. During the grace window every event arrives with TWO signatures in the `X-Key2Pay-Signature` header — `v1=<hash-with-new>,v0=<hash-with-old>` — and your handler should accept either.

Server-side authentication
Authentication guide
Key2Pay Developer documentationAPI v1
Documentation
Dashboard