# webhooks.rotateSecret Rotate the signing secret in the authenticated project environment. ## Import and client ```ts import { RelayServer } from '@relayrtc/node' const relay = new RelayServer({ apiUrl: process.env.RELAYRTC_API_URL!, apiKey: process.env.RELAYRTC_SECRET_KEY!, }) ``` ## Requirements The API must have signing encryption configured. Otherwise this operation throws WEBHOOK_SIGNING_UNAVAILABLE with HTTP status 503. A secret key with `webhooks:write`. The requested resource must belong to that key's project environment. ## Parameters | Option | Type | Default / requirement | Purpose | | --- | --- | --- | --- | | endpointId | string | Required | ID returned when creating the webhook. | | projectId | string | Key project | Must match the key's project. | | environmentId | string | Key environment | Must match the key's environment. | Every method accepts [RequestOptions](/reference/sdk/server/node/request-options) as its final argument. Optional scope parameters go before RequestOptions. They cannot expand the key’s project or environment. ## Example ```ts const endpointId = 'webhook_example' const result = await relay.webhooks.rotateSecret(endpointId) ``` ## Returns `Promise`. Returns the endpoint, new signing secret and `rotationPolicy: "immediate replacement"`. ## Behavior > **Immediate replacement** > The previous signing secret stops being current immediately. Save the new secret and update your receiver. ## REST equivalent [`POST /v1/webhooks/{endpointId}/rotate-secret`](/reference/api/v1/webhooks/rotate-secret). Failures throw [RelayApiError](/reference/sdk/server/node/RelayApiError).