> ## Documentation Index
> Fetch the complete documentation index at: https://docs.staging.cope-demo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate a webhook endpoint signing secret



## OpenAPI

````yaml /api-reference/account-platform-webhooks-v1.openapi.json post /v1/webhooks/endpoints/{id}/secret-rotations
openapi: 3.1.0
info:
  title: COPE Public API
  version: 1.0.0
servers:
  - url: https://api.cope.com
security: []
paths:
  /v1/webhooks/endpoints/{id}/secret-rotations:
    post:
      summary: Rotate a webhook endpoint signing secret
      operationId: webhooks.endpoints.secret_rotations.create
      parameters:
        - in: path
          name: id
          required: true
          schema:
            pattern: ^whs_[A-Za-z0-9_-]+$
            type: string
        - description: >-
            Required. At most 255 characters of valid UTF-8 with no NUL byte; a
            missing key is refused with 400 `idempotency_key_required` and a
            malformed one with 400 `invalid_idempotency_key`. A retry with the
            same key and body returns the original successful response for 24
            hours; a request that failed can be sent again under the same key.
            The same key with a different body is refused with 409
            `idempotency_key_conflict`, and while the first request is still
            running with 409 `idempotency_key_in_progress` and a `Retry-After`
            header.
          in: header
          name: Idempotency-Key
          required: true
          schema:
            maxLength: 255
            minLength: 1
            type: string
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebhookEndpointSecretResponse'
          description: >-
            Rotated webhook endpoint signing secret. A retry with the same
            `Idempotency-Key` returns the same body minus `signing_secret`
            (`WebhookEndpointSecretReplayResponse`): the stored idempotent
            response holds no copy of the secret. If the first response was
            lost, rotate the secret under a new `Idempotency-Key`.
          x-cope-idempotent-replay:
            schema:
              $ref: '#/components/schemas/WebhookEndpointSecretReplayResponse'
        '400':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
          description: Bad Request
        '401':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
          description: Unauthorized
        '403':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
          description: Forbidden
        '404':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
          description: Not Found
        '409':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
          description: >-
            `idempotency_key_conflict` (the key was used with a different body)
            or `idempotency_key_in_progress` (the first request is still
            running; retry after `Retry-After`).
      security:
        - bearerAuth: []
components:
  schemas:
    WebhookEndpointSecretResponse:
      properties:
        data:
          $ref: '#/components/schemas/WebhookEndpointSecret'
      required:
        - data
      type: object
    Problem:
      additionalProperties: false
      properties:
        code:
          type: string
        detail:
          type: string
        errors:
          items:
            additionalProperties: false
            properties:
              code:
                type: string
              detail:
                type: string
              param:
                description: >-
                  The request field refused; absent when the refusal is about
                  the request as a whole.
                type: string
            required:
              - code
              - detail
            type: object
          type: array
        request_id:
          type: string
        status:
          type: integer
        title:
          type: string
        type:
          format: uri
          type: string
      required:
        - type
        - title
        - status
        - code
        - errors
      type: object
    WebhookEndpointSecret:
      properties:
        active:
          type: boolean
        created_at:
          format: date-time
          type: string
        description:
          type:
            - string
            - 'null'
        disabled_reason:
          type:
            - string
            - 'null'
        event_types:
          items:
            type: string
          type: array
        id:
          pattern: ^whs_[A-Za-z0-9_-]+$
          type: string
        notification_email:
          format: email
          type: string
        signing_secret:
          pattern: ^whsec_[A-Za-z0-9_-]+$
          type: string
        updated_at:
          format: date-time
          type: string
        url:
          format: uri
          type: string
      required:
        - id
        - url
        - active
        - notification_email
        - event_types
        - created_at
        - updated_at
        - signing_secret
      type: object
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.