# Replace example resource IDs and ownerId with values from your workspace.
: "${POWERDIALER_API_KEY:?Set POWERDIALER_API_KEY to your scoped API key}"
curl --request POST \
--url 'https://api.migration.powerdialer.ai/api/public/v2/webhooks/00000000-0000-4000-8000-000000000001/rotate-secret' \
--header "Authorization: Bearer $POWERDIALER_API_KEY"{
"id": "00000000-0000-4000-8000-000000000001",
"signingSecret": "example-signing-secret-replace-with-the-returned-value",
"active": false
}{
"error": {
"code": "invalid_api_key",
"message": "API key is invalid, expired or revoked",
"requestId": "00000000-0000-4000-8000-000000000004"
}
}Rotate a webhook signing secret
Generate a replacement signing secret for a v2 receiver, including the first secret you configure after creating a subscription. Requires webhooks:manage and the owning credential. There is no request body. The response exposes signingSecret once and reports active:false.
Rotation immediately replaces the old secret, pauses the subscription and clears verification. Store the new value in your receiver’s secret manager, update signature verification, then call the verification endpoint to resume delivery. Queued deliveries encountered while inactive can become cancelled and need explicit replay. API-key rotation in Developers is separate and does not change this secret.
This operation does not use an idempotency receipt. Never automatically retry it, even if you supply an Idempotency-Key. If the response is lost, explicitly rotate again, save that new secret and reverify before relying on delivery. 404 not_found requires checking the subscription and originating credential; a 503 needs service investigation before deliberate recovery.
See signing and setup.
# Replace example resource IDs and ownerId with values from your workspace.
: "${POWERDIALER_API_KEY:?Set POWERDIALER_API_KEY to your scoped API key}"
curl --request POST \
--url 'https://api.migration.powerdialer.ai/api/public/v2/webhooks/00000000-0000-4000-8000-000000000001/rotate-secret' \
--header "Authorization: Bearer $POWERDIALER_API_KEY"{
"id": "00000000-0000-4000-8000-000000000001",
"signingSecret": "example-signing-secret-replace-with-the-returned-value",
"active": false
}{
"error": {
"code": "invalid_api_key",
"message": "API key is invalid, expired or revoked",
"requestId": "00000000-0000-4000-8000-000000000004"
}
}Authorizations
Issued in Developers. Workspace/owner/scopes come from credential, never acting-user headers. API keys cannot manage API credentials.
Path Parameters
Subscription UUID returned by registration or listing. It must belong to the credential making this request.
Response
A one-time replacement signing secret. The receiver is paused and must be verified again.