# Rotate Webhook Secret

> POST /webhooks/:id/rotate — replace the signing secret for a webhook.

`POST /webhooks/:id/rotate`

Rotates the signing secret for a webhook, invalidating the old secret immediately. Use this if your current secret has been compromised or as part of a regular credential rotation policy. The new plaintext secret is returned **once** in this response — store it securely before the request completes.

**Path parameters**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `id` | string | Yes | The webhook id as returned by [Create Webhook](https://www.senddart.com/docs/api/webhooks-create) or [List Webhooks](https://www.senddart.com/docs/api/webhooks-list) — a numeric string (e.g. `17`), not a UUID. A non-numeric id returns `not_found` (404). |

**Node.js**

```js
import { SendDart } from 'senddart';

const mb = new SendDart('mb_xxxxxxxxx');

const { data, error } = await mb.webhooks.rotate('17');
console.log({ data, error });
```

**Ruby**

```ruby
require "senddart"

SendDart.api_key = "mb_xxxxxxxxx"

SendDart::Webhooks.rotate("17")
```

**PHP**

```php
<?php
require 'vendor/autoload.php';

use SendDart\SendDart;

$senddart = SendDart::client('mb_xxxxxxxxx');

$senddart->webhooks->rotate('17');
```

**Python**

```python
import senddart

senddart.api_key = "mb_xxxxxxxxx"

senddart.Webhooks.rotate("17")
```

**Go**

```go
import "github.com/shekhu10/senddart-sdks/senddart-go"

client := senddart.NewClient("mb_xxxxxxxxx")

rotated, err := client.Webhooks.Rotate("17")
```

**Rust**

```rust
use senddart::SendDart;

let mb = SendDart::new("mb_xxxxxxxxx");

let _rotated = mb.webhooks.rotate("17").await?;
```

**Java**

```java
import com.senddart.SendDart;
import com.senddart.SendDartResponse;

SendDart senddart = new SendDart("mb_xxxxxxxxx");

SendDartResponse response = senddart.webhooks().rotate("17");
```

**.NET**

```csharp
using SendDart;

ISendDart senddart = SendDartClient.Create("mb_xxxxxxxxx");

var resp = await senddart.WebhookRotateAsync("17");
```

**cURL**

```bash
curl -X POST 'https://www.senddart.com/api/webhooks/17/rotate' \
  -H 'Authorization: Bearer mb_xxxxxxxxx'
```

**CLI**

```bash
senddart webhooks rotate 17
```

### Response

```json
{
  "object": "webhook",
  "id": "17",
  "signing_secret": "whsec_xxxxxxxxxx"
}
```

> **Warning:** The new `signing_secret` is only returned here, at rotation. The old secret stops working immediately. Store the new value securely — it cannot be retrieved again.
