Docs
REST API v1

Rotate the signing secret

Rotate the signing secret in the authenticated project environment.

POST/v1/webhooks/{endpointId}/rotate-secret

Requirements

A secret API key with webhooks:write. Resources are restricted to the key's project and environment.

Path parameters

NameTypeRequired / defaultDescription
endpointIdstringRequiredID returned when creating the webhook.

Query parameters

NameTypeRequired / defaultDescription
projectIdstringKey projectMust match the key's project.
environmentIdstringKey environmentMust match the key's environment.

Request body

Send an empty JSON object.

Example

Set RELAYRTC_API_URL to your API base including /v1, such as http://localhost:8082/v1.

Shell
curl -X POST "$RELAYRTC_API_URL/webhooks/webhook_example/rotate-secret" \
  -H "Authorization: Bearer $RELAYRTC_SECRET_KEY" \
  -H "Content-Type: application/json" \
  -d '{}'

Response

200 with the endpoint, new signing secret and rotationPolicy: "immediate replacement".

JSON
{
  "id": "webhook_example",
  "projectId": "project_example",
  "environmentId": "environment_example",
  "url": "https://your-app.example/webhooks/relayrtc",
  "eventTypes": [
    "room.ended"
  ],
  "status": "enabled",
  "signingSecretVersion": 2,
  "signingSecretRotatedAt": "2026-01-01T12:00:00.000Z",
  "createdAt": "2026-01-01T12:00:00.000Z",
  "updatedAt": "2026-01-01T12:00:00.000Z",
  "signingSecret": "whsec_example_save_the_returned_secret",
  "rotationPolicy": "immediate replacement"
}

Notes

Immediate replacement

The previous signing secret stops being current immediately. Save the new secret and update your receiver.

Errors

503 WEBHOOK_SIGNING_UNAVAILABLE means signing encryption is not configured on the API.

Invalid fields return 400. Invalid credentials return 401; a missing scope returns 403. A missing resource returns 404. See error responses.