# Rotate the signing secret Rotate the signing secret in the authenticated project environment. ## Requirements A secret API key with `webhooks:write`. Resources are restricted to the key's project and environment. ## Path parameters | Name | Type | Required / default | Description | | --- | --- | --- | --- | | endpointId | string | Required | ID returned when creating the webhook. | ## Query parameters | Name | Type | Required / default | Description | | --- | --- | --- | --- | | projectId | string | Key project | Must match the key's project. | | environmentId | string | Key environment | Must match the key's environment. | ## Request body Send an empty JSON object. ## Example Set `RELAYRTC_API_URL` to your API base including `/v1`, such as `http://localhost:8082/v1`. ```bash curl -X POST "$RELAYRTC_API_URL/webhooks/webhook_example/rotate-secret" \ -H "Authorization: Bearer $RELAYRTC_SECRET_KEY" \ -H "Content-Type: application/json" \ -d '{}' ``` ## Response `200` with the endpoint, new signing secret and `rotationPolicy: "immediate replacement"`. ```json { "id": "webhook_example", "projectId": "project_example", "environmentId": "environment_example", "url": "https://your-app.example/webhooks/relayrtc", "eventTypes": [ "room.ended" ], "status": "enabled", "signingSecretVersion": 2, "signingSecretRotatedAt": "2026-01-01T12:00:00.000Z", "createdAt": "2026-01-01T12:00:00.000Z", "updatedAt": "2026-01-01T12:00:00.000Z", "signingSecret": "whsec_example_save_the_returned_secret", "rotationPolicy": "immediate replacement" } ``` ## Notes > **Immediate replacement** > The previous signing secret stops being current immediately. Save the new secret and update your receiver. ## Errors `503 WEBHOOK_SIGNING_UNAVAILABLE` means signing encryption is not configured on the API. Invalid fields return `400`. Invalid credentials return `401`; a missing scope returns `403`. A missing resource returns `404`. See [error responses](/reference/api/v1/errors).