> ## Documentation Index
> Fetch the complete documentation index at: https://www.commercengine.io/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate Webhook Secret

> Rotate the webhook's HMAC secret. The new secret is returned once and used to sign future webhook requests.



## OpenAPI

````yaml https://openapi.commercengine.io/ce-admin.json post /webhooks/{webhook_id}/rotate-secret
openapi: 3.1.0
info:
  title: CE Admin APIs
  version: '1.0'
  summary: Comprehensive admin interface for managing your e-commerce platform
  description: >-
    Complete administrative API suite for Commerce Engine, providing powerful
    tools to manage products, orders, customers, inventory, analytics, and
    system configuration. Designed for administrators and backend integrations
    requiring full platform control.
  license:
    name: All Rights Reserved
    url: https://www.commercengine.io/contact-us
  contact:
    email: support@commercengine.io
    url: https://www.commercengine.io/contact-us
    name: Support
servers:
  - url: https://staging.api.commercengine.io/api/v1/{store_id}/admin
    description: Staging Server
    variables:
      store_id:
        default: store_id
        description: Store ID
  - url: https://prod.api.commercengine.io/api/v1/{store_id}/admin
    description: Prod Server
    variables:
      store_id:
        default: store_id
        description: Store ID
security:
  - Authorization: []
tags:
  - name: Analytics
    description: Analytics
  - name: Catalog
    description: Catalog
  - name: Coupons & promotions
    description: Coupons & promotions
  - name: Customers
    description: Customers
  - name: Filter Options
    description: Filter Options
  - name: Inventories
    description: Inventories
  - name: Marketplace
    description: Marketplace
  - name: Marketplace Catalog
    description: Marketplace Catalog
  - name: Media Gallery
    description: Media Gallery
  - name: Metrics
    description: Metrics
  - name: Orders
    description: Orders
  - name: Payments
    description: Payments
  - name: Payouts
    description: Payouts
  - name: POS
    description: POS
  - name: POSAdmin
    description: Admin endpoints to be used as proxy in pos
  - name: Segments
    description: Segments
  - name: Shipping
    description: Shipping
  - name: SSE
    description: SSE
  - name: Store
    description: Store
  - name: Webhooks
    description: Webhooks
paths:
  /webhooks/{webhook_id}/rotate-secret:
    parameters:
      - name: webhook_id
        in: path
        description: Webhook ID
        required: true
        schema:
          type: string
    post:
      tags:
        - Webhooks
      summary: Rotate Webhook Secret
      description: >-
        Rotate the webhook's HMAC secret. The new secret is returned once and
        used to sign future webhook requests.
      operationId: rotate-webhook-secret
      responses:
        '200':
          description: Secret rotated successfully
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                  - message
                  - content
                properties:
                  success:
                    type: boolean
                  message:
                    type: string
                  content:
                    properties:
                      webhook_secret_key:
                        description: The new HMAC secret key (only shown once)
                        type: string
                        example: >-
                          whsec_c8a0f9d7a12fbc1f388db1c621730fb935182ef918de3b7e36e77dcf99c44f9
                    required:
                      - webhook_secret_key
                    type: object
              examples:
                default:
                  value:
                    success: true
                    message: Webhook secret rotated successfully
                    content:
                      webhook_secret_key: >-
                        whsec_c8a0f9d7a12fbc1f388db1c621730fb935182ef918de3b7e36e77dcf99c44f9
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
components:
  responses:
    Unauthorized:
      description: Not authorized for given operation on the Resource
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
                example: Not authorized for given operation on the Resource.
              success:
                type: boolean
                default: false
              code:
                type: string
                example: unauthorized
    NotFound:
      description: Requested resource not found
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
              success:
                type: boolean
              code:
                type: string
  securitySchemes:
    Authorization:
      type: http
      scheme: bearer

````