# Rotate Signing Secret

POST

/

webhooks

/

:webhook\_id

/

signing-secret

/

rotate

:::code-group
```typescript title="Node.js"
import { Resend } from 'resend';

const resend = new Resend('re_xxxxxxxxx');

const { data, error } = await resend.webhooks.rotateSigningSecret(
  '4dd369bc-aa82-4ff3-97de-514ae3000ee0',
);
```

```php title="PHP"
$resend = Resend::client('re_xxxxxxxxx');

$webhook = $resend->webhooks->rotateSigningSecret(
    '4dd369bc-aa82-4ff3-97de-514ae3000ee0'
);
```

```python title="Python"
import resend

resend.api_key = 're_xxxxxxxxx'

webhook = resend.Webhooks.rotate_signing_secret(
    webhook_id='4dd369bc-aa82-4ff3-97de-514ae3000ee0',
)
```

```ruby title="Ruby"
require 'resend'

Resend.api_key = 're_xxxxxxxxx'

webhook = Resend::Webhooks.rotate_signing_secret(
  '4dd369bc-aa82-4ff3-97de-514ae3000ee0'
)
```

```go title="Go"
package main

import "github.com/resend/resend-go/v4"

func main() {
	client := resend.NewClient("re_xxxxxxxxx")

	client.Webhooks.RotateSigningSecret(
		"4dd369bc-aa82-4ff3-97de-514ae3000ee0",
	)
}
```

```rust title="Rust"
use resend_rs::{Resend, Result};

#[tokio::main]
async fn main() -> Result<()> {
  let resend = Resend::new("re_xxxxxxxxx");

  let _webhook = resend
    .webhooks
    .rotate_signing_secret("4dd369bc-aa82-4ff3-97de-514ae3000ee0")
    .await?;

  Ok(())
}
```

```java title="Java"
import com.resend.Resend;
import com.resend.core.exception.ResendException;
import com.resend.services.webhooks.model.RotateWebhookSigningSecretResponseSuccess;

public class Main {
    public static void main(String[] args) throws ResendException {
        Resend resend = new Resend("re_xxxxxxxxx");

        RotateWebhookSigningSecretResponseSuccess webhook = resend.webhooks().rotateSigningSecret(
            "4dd369bc-aa82-4ff3-97de-514ae3000ee0"
        );
    }
}
```

```csharp title=".NET"
using Resend;

IResend resend = ResendClient.Create( "re_xxxxxxxxx" ); // Or from DI

var resp = await resend.WebhookRotateSigningSecretAsync(
    new Guid( "4dd369bc-aa82-4ff3-97de-514ae3000ee0" )
);
Console.WriteLine( "Signing secret={0}", resp.Content.SigningSecret );
```

```shellscript title="cURL"
curl -X POST 'https://api.resend.com/webhooks/4dd369bc-aa82-4ff3-97de-514ae3000ee0/signing-secret/rotate' \
     -H 'Authorization: Bearer re_xxxxxxxxx'
```

```shellscript title="CLI"
resend webhooks rotate-signing-secret 4dd369bc-aa82-4ff3-97de-514ae3000ee0
```
:::

:::code-group
```json title="Response"
{
  "object": "webhook",
  "id": "4dd369bc-aa82-4ff3-97de-514ae3000ee0",
  "signing_secret": "whsec_xxxxxxxxxx"
}
```
:::

:::callout{intent="note"}
For 24 hours after the rotation, payloads are signed with both the new and the previous secret, so either one verifies them. After that, only the new secret does. Use that window to update the secret your application uses to [verify requests](/guides/learn-webhooks-verify-webhooks-requests) without dropping events.
:::

## Path Parameters

## Response Fields

string

Always `webhook`.

string

The Webhook ID.

string

The new signing secret.

:::code-group
```typescript title="Node.js"
import { Resend } from 'resend';

const resend = new Resend('re_xxxxxxxxx');

const { data, error } = await resend.webhooks.rotateSigningSecret(
  '4dd369bc-aa82-4ff3-97de-514ae3000ee0',
);
```

```php title="PHP"
$resend = Resend::client('re_xxxxxxxxx');

$webhook = $resend->webhooks->rotateSigningSecret(
    '4dd369bc-aa82-4ff3-97de-514ae3000ee0'
);
```

```python title="Python"
import resend

resend.api_key = 're_xxxxxxxxx'

webhook = resend.Webhooks.rotate_signing_secret(
    webhook_id='4dd369bc-aa82-4ff3-97de-514ae3000ee0',
)
```

```ruby title="Ruby"
require 'resend'

Resend.api_key = 're_xxxxxxxxx'

webhook = Resend::Webhooks.rotate_signing_secret(
  '4dd369bc-aa82-4ff3-97de-514ae3000ee0'
)
```

```go title="Go"
package main

import "github.com/resend/resend-go/v4"

func main() {
	client := resend.NewClient("re_xxxxxxxxx")

	client.Webhooks.RotateSigningSecret(
		"4dd369bc-aa82-4ff3-97de-514ae3000ee0",
	)
}
```

```rust title="Rust"
use resend_rs::{Resend, Result};

#[tokio::main]
async fn main() -> Result<()> {
  let resend = Resend::new("re_xxxxxxxxx");

  let _webhook = resend
    .webhooks
    .rotate_signing_secret("4dd369bc-aa82-4ff3-97de-514ae3000ee0")
    .await?;

  Ok(())
}
```

```java title="Java"
import com.resend.Resend;
import com.resend.core.exception.ResendException;
import com.resend.services.webhooks.model.RotateWebhookSigningSecretResponseSuccess;

public class Main {
    public static void main(String[] args) throws ResendException {
        Resend resend = new Resend("re_xxxxxxxxx");

        RotateWebhookSigningSecretResponseSuccess webhook = resend.webhooks().rotateSigningSecret(
            "4dd369bc-aa82-4ff3-97de-514ae3000ee0"
        );
    }
}
```

```csharp title=".NET"
using Resend;

IResend resend = ResendClient.Create( "re_xxxxxxxxx" ); // Or from DI

var resp = await resend.WebhookRotateSigningSecretAsync(
    new Guid( "4dd369bc-aa82-4ff3-97de-514ae3000ee0" )
);
Console.WriteLine( "Signing secret={0}", resp.Content.SigningSecret );
```

```shellscript title="cURL"
curl -X POST 'https://api.resend.com/webhooks/4dd369bc-aa82-4ff3-97de-514ae3000ee0/signing-secret/rotate' \
     -H 'Authorization: Bearer re_xxxxxxxxx'
```

```shellscript title="CLI"
resend webhooks rotate-signing-secret 4dd369bc-aa82-4ff3-97de-514ae3000ee0
```
:::

```json
{
  "object": "webhook",
  "id": "4dd369bc-aa82-4ff3-97de-514ae3000ee0",
  "signing_secret": "whsec_xxxxxxxxxx"
}
```

Was this page helpful?

⌘I

## Related pages

- [Account Management](./account-management-index.md)
- [API Keys](./api-keys-2-index.md)
- [API Keys](./api-keys-index.md)
- [API Reference](./api-reference-index.md)
- [AudiencesDEPRECATED](./audiencesdeprecated-index.md)
- [Authorized Apps](./authorized-apps-index.md)
- [Automations](./automations-index.md)
- [Broadcasts](./broadcasts-index.md)
- [Build with AI](./build-with-ai-index.md)
- [Changelog](../changelog.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
