> ## Documentation Index
> Fetch the complete documentation index at: https://docs.photon.codes/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate Standard Webhooks secret

> Creates a new `whsec_` secret. For the overlap period, deliveries contain signatures for both the new and previous secret so consumers can switch without downtime. The legacy Spectrum secret is unchanged.



## OpenAPI

````yaml https://spectrum.photon.codes/openapi/json post /projects/{projectId}/webhooks/{webhookId}/secret/rotate
openapi: 3.1.0
info:
  title: Spectrum Cloud External API
  description: Client-facing API for Spectrum Cloud.
  version: 1.0.0
servers:
  - url: https://spectrum.photon.codes
security: []
tags:
  - name: billing
    description: Billing and subscription operations
  - name: imessage
    description: iMessage platform operations
  - name: lines
    description: Phone line enumeration across platforms
  - name: platforms
    description: Platform management operations
  - name: users
    description: User operations
  - name: voice
    description: Voice platform operations
  - name: webhooks
    description: Webhook registration for receiving Spectrum events
  - name: whatsapp-business
    description: WhatsApp Business platform operations
  - name: slack
    description: Slack platform operations
paths:
  /projects/{projectId}/webhooks/{webhookId}/secret/rotate:
    post:
      tags:
        - webhooks
      summary: Rotate Standard Webhooks secret
      description: >-
        Creates a new `whsec_` secret. For the overlap period, deliveries
        contain signatures for both the new and previous secret so consumers can
        switch without downtime. The legacy Spectrum secret is unchanged.
      operationId: postProjectsByProjectIdWebhooksByWebhookIdSecretRotate
      parameters:
        - name: webhookId
          in: path
          required: true
          schema:
            type: string
            format: uuid
            pattern: >-
              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
        - name: projectId
          in: path
          required: true
          schema:
            type: string
            format: uuid
            pattern: >-
              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                overlapSeconds:
                  default: 86400
                  type: integer
                  minimum: 0
                  maximum: 604800
              required:
                - overlapSeconds
              additionalProperties: false
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                overlapSeconds:
                  default: 86400
                  type: integer
                  minimum: 0
                  maximum: 604800
              required:
                - overlapSeconds
              additionalProperties: false
          multipart/form-data:
            schema:
              type: object
              properties:
                overlapSeconds:
                  default: 86400
                  type: integer
                  minimum: 0
                  maximum: 604800
              required:
                - overlapSeconds
              additionalProperties: false
      responses:
        '200':
          description: Response for status 200
          content:
            application/json:
              schema:
                type: object
                properties:
                  succeed:
                    type: boolean
                    const: true
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        pattern: >-
                          ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      standardSigningSecret:
                        type: string
                        pattern: ^whsec_.*
                      previousValidUntil:
                        anyOf:
                          - type: string
                            format: date-time
                            pattern: >-
                              ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
                          - type: 'null'
                    required:
                      - id
                      - standardSigningSecret
                      - previousValidUntil
                    additionalProperties: false
                required:
                  - succeed
                  - data
                additionalProperties: false

````