> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ando.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate webhook endpoint secret

> Rotates a webhook endpoint signing secret and returns the new secret exactly once.



## OpenAPI

````yaml /api-reference/openapi.json post /webhook-endpoints/{endpointId}/rotate-secret
openapi: 3.0.3
info:
  description: >-
    Generated from Ando's accepted public API v1 contract metadata. Current
    routes preserve legacy /api/v1 response envelopes while converging on the
    public https://api.ando.so/v1 shape.
  title: Ando Public API
  version: v1
servers:
  - description: Canonical public API host.
    url: https://api.ando.so/v1
security: []
tags:
  - description: Call detail and transcript routes.
    name: Calls
  - description: Clipboard detail routes.
    name: Clipboards
  - description: >-
      Workspace member detail routes. Existing v1 paths keep member
      compatibility spellings.
    name: Members
  - description: Message and conversation message routes.
    name: Messages
  - description: Public realtime connection and protocol routes.
    name: Realtime
  - description: Search routes.
    name: Search
  - description: Task routes.
    name: Tasks
  - description: Outbound webhook endpoint and delivery routes.
    name: Webhooks
paths:
  /webhook-endpoints/{endpointId}/rotate-secret:
    post:
      tags:
        - Webhooks
      summary: Rotate webhook endpoint secret
      description: >-
        Rotates a webhook endpoint signing secret and returns the new secret
        exactly once.
      operationId: rotateWebhookEndpointSecret
      parameters:
        - description: Webhook endpoint identifier.
          in: path
          name: endpointId
          required: true
          schema:
            description: Webhook endpoint identifier.
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RotateWebhookEndpointSecretBody'
        required: false
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebhookEndpointSecretResponse'
          description: Rotated webhook endpoint secret.
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
      security:
        - AndoApiKey: []
        - BearerApiKey: []
components:
  schemas:
    RotateWebhookEndpointSecretBody:
      additionalProperties: false
      description: Webhook endpoint secret rotation request.
      properties:
        previous_secret_ttl_seconds:
          description: Seconds to keep the previous secret active. Maximum is 86400.
          type: integer
          minimum: 0
      type: object
    WebhookEndpointSecretResponse:
      additionalProperties: false
      description: Webhook endpoint response with one-time plaintext secret.
      properties:
        data:
          $ref: '#/components/schemas/WebhookEndpointSecret'
      required:
        - data
      type: object
    WebhookEndpointSecret:
      additionalProperties: false
      description: Webhook endpoint response with one-time plaintext secret.
      properties:
        created_at:
          description: Endpoint creation timestamp.
          type: string
          example: '2026-05-14T08:00:00.000Z'
          format: date-time
        delivery_scope:
          $ref: '#/components/schemas/WebhookEndpointDeliveryScope'
        disabled_at:
          description: Endpoint disabled timestamp.
          type: string
          format: date-time
          nullable: true
        enabled_events:
          description: Product event types delivered to this endpoint.
          items:
            description: Webhook event type.
            enum:
              - message.created
              - message.updated
              - conversation.membership.created
              - conversation.archived
              - conversation.unarchived
              - call.started
              - call.ended
              - call.updated
              - call.transcript.updated
              - webhook.test
            type: string
          type: array
        id:
          description: Webhook endpoint identifier.
          type: string
          example: 01jzn7e61x3a7v9h2r7t2m3q4p
        name:
          description: Endpoint label.
          type: string
          nullable: true
        object:
          description: Object type.
          enum:
            - webhook_endpoint
          type: string
        previous_signing_secret_expires_at:
          description: Previous secret expiration timestamp.
          type: string
          format: date-time
          nullable: true
        signing_secret_prefix:
          description: Display-safe prefix of the active signing secret.
          type: string
        status:
          description: Endpoint status.
          enum:
            - active
            - disabled
          type: string
        updated_at:
          description: Last update timestamp.
          type: string
          example: '2026-05-14T08:00:00.000Z'
          format: date-time
        url:
          description: Receiver URL.
          type: string
        workspace_id:
          description: Workspace identifier.
          type: string
          example: 01jzn7e61x3a7v9h2r7t2m3q4p
        signing_secret:
          description: Plaintext webhook signing secret. Store it immediately.
          type: string
      required:
        - object
        - id
        - workspace_id
        - name
        - url
        - enabled_events
        - delivery_scope
        - status
        - signing_secret_prefix
        - previous_signing_secret_expires_at
        - disabled_at
        - created_at
        - updated_at
        - signing_secret
      type: object
    LegacyErrorResponse:
      additionalProperties: false
      description: Current compatibility error envelope used by legacy /api/v1 routes.
      properties:
        error:
          description: Error message.
          type: string
        error_code:
          description: Optional machine-readable error code.
          type: string
          nullable: true
        missing_scopes:
          description: Missing scopes.
          items:
            description: Scope.
            type: string
          type: array
      required:
        - error
      type: object
    PublicApiErrorResponse:
      additionalProperties: false
      description: Target public API error envelope.
      properties:
        error:
          additionalProperties: false
          description: Error details.
          properties:
            code:
              description: Machine-readable error code.
              type: string
            message:
              description: Human-readable error message.
              type: string
            request_id:
              description: Request identifier.
              type: string
              nullable: true
          required:
            - code
            - message
          type: object
      required:
        - error
      type: object
    WebhookEndpointDeliveryScope:
      description: Webhook endpoint runtime data recipient.
      oneOf:
        - additionalProperties: false
          description: Member-targeted endpoint delivery scope.
          properties:
            actor_workspace_membership_id:
              description: Workspace membership the endpoint acts as.
              type: string
              example: 01jzn7e61x3a7v9h2r7t2m3q4p
            direct_message_delivery_enabled:
              description: >-
                Whether direct-message events are delivered for conversations
                the actor belongs to.
              type: boolean
            type:
              description: Delivery scope type.
              enum:
                - workspace_member
              type: string
          required:
            - type
            - actor_workspace_membership_id
            - direct_message_delivery_enabled
          type: object
        - additionalProperties: false
          description: Unsupported workspace export placeholder.
          properties:
            status:
              description: Workspace export approval state.
              enum:
                - unsupported
                - requires_approval
                - approved
              type: string
            type:
              description: Delivery scope type.
              enum:
                - workspace_export
              type: string
          required:
            - type
            - status
          type: object
  responses:
    BadRequest:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/LegacyErrorResponse'
      description: Bad request.
    Unauthorized:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/LegacyErrorResponse'
      description: Missing or invalid API key.
    Forbidden:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/LegacyErrorResponse'
      description: Forbidden.
    NotFound:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/LegacyErrorResponse'
      description: Not found.
    Conflict:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/LegacyErrorResponse'
      description: Conflict.
    RateLimited:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PublicApiErrorResponse'
      description: Rate limit or quota exceeded.
    InternalError:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/LegacyErrorResponse'
      description: Internal server error.
  securitySchemes:
    AndoApiKey:
      description: Workspace API key. Current accepted keys use the ando_sk_ prefix.
      in: header
      name: x-api-key
      type: apiKey
    BearerApiKey:
      bearerFormat: ando_sk
      description: Compatibility transport for workspace API keys.
      scheme: bearer
      type: http

````