> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentlinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate webhook secret

> Add a second active signing secret, or retire the older one.

`rotate_webhook_secret`

Add a second active signing secret, or retire the older one. Both secrets sign every request while two are active, so a receiver updates its configuration whenever it likes rather than deploying in lockstep with us. The new secret is returned ONCE.

<Note>Hosted MCP registration verified. These schemas describe the development contract; confirm supported inputs with tools/list. Generic CLI/HTTP calls require a matching development server. Configure LINKTRAIL\_API\_URL; production does not expose these command routes.</Note>

| Access          | Behavior                                                   |
| --------------- | ---------------------------------------------------------- |
| `watches:write` | Writes or admits work; can change or remove existing state |

Reading saved data does not start a verification job. Mutations can change saved records or access; the effects below apply.

## Example request

Connect through [MCP](/guides/connect-mcp), [CLI](/guides/connect-cli), or [HTTP](/guides/connect-http). Replace example identifiers with records from your workspace.

<CodeGroup>
  ```json MCP theme={null}
  {
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "rotate_webhook_secret",
      "arguments": {
        "endpointId": "endpoint_example"
      }
    }
  }
  ```

  ```bash CLI theme={null}
  linktrail call rotate_webhook_secret --args '{"endpointId":"endpoint_example"}'
  ```

  ```bash HTTP theme={null}
  curl "$LINKTRAIL_API_URL/v1/commands/rotate_webhook_secret" \
    -H "Authorization: Bearer $LINKTRAIL_API_KEY" \
    -H 'Content-Type: application/json' \
    --data '{"endpointId":"endpoint_example"}'
  ```
</CodeGroup>

## Returned result

Illustrative data validated against the documented response schema. IDs and dates are examples, not a live account capture. MCP returns this data in `structuredContent` and in a text content block; generic HTTP and CLI return the JSON result directly.

```json theme={null}
{
  "id": "endpoint_example",
  "active_secrets": 2,
  "retired": false,
  "secret": "whsec_example_not_a_credential"
}
```

## Input fields

Omit optional fields when you do not want to supply them. Null is accepted only where listed. Unknown input properties are rejected.

| Field        | Type    | Presence | Meaning and constraints                                                                                                                                                |
| ------------ | ------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `endpointId` | string  | Required | Identifier of the endpoint returned by its create or list operation. minLength: 1; maxLength: 200                                                                      |
| `retire`     | boolean | Optional | First call with false to issue a new secret, save it and update the receiver. Then call with true to retire the older secret; true alone never rotates. default: false |

### Validation and omitted values

With retire omitted or false, add a new secret. Store and test it before calling with retire:true to remove the older secret. Both secrets sign during overlap.

### Defaults when omitted

| Field    | Default |
| -------- | ------- |
| `retire` | `false` |

## Output fields

Fields inside optional or nullable parents apply only when that parent exists. [Common schema conventions](/reference/schemas) explain evidence states, empty lists and extensions.

| Field            | Type    | Presence | Meaning and constraints                                                          |
| ---------------- | ------- | -------- | -------------------------------------------------------------------------------- |
| `id`             | string  | Required | Resource identifier returned by the operation.                                   |
| `active_secrets` | number  | Required | active secrets recorded for this result.                                         |
| `retired`        | boolean | Required | retired recorded for this result.                                                |
| `secret`         | string  | Optional | Webhook signing secret returned only when created or rotated. Store it securely. |

[Download input schema](/schemas/rotate_webhook_secret.input.json) · [Download output schema](/schemas/rotate_webhook_secret.output.json)

## Errors and retries

This command is not annotated idempotent. After a timeout, inspect existing state before repeating a write.

See [error recovery](/reference/errors) for status, scope, cooldown, cursor and retry handling. Unknown observations are result data and do not establish loss.

## HTTP resource routes

These existing resource routes share the operation’s domain behavior. Their parameter placement, status and response envelope can differ from generic invocation. See [HTTP route details](/reference/http/routes).

| Method and route                         | Success | Details                                                                                                                                                           |
| ---------------------------------------- | ------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `POST /v1/webhooks/{endpointId}/secrets` | 201     | Remaining arguments go in a JSON object body. Empty or unreadable body is treated as \{} by this resource handler; use \{retire:true} to retire the older secret. |

## Continue

[list\_webhooks](/reference/commands/list_webhooks)

Follow the [related workflow](/guides/webhooks), inspect [capability status](/capability-status), or return to the [command index](/reference/index).
