Skip to main content
POST
Rotate webhook signing secret

Authorizations

Authorization
string
header
required

Account Service Key, prefixed with pho_ask_, sent as Authorization: Bearer <key>. Acts on behalf of its owning account, subject to the permissions and credential restrictions of each operation. Account access tokens and OAuth grants also use the Bearer header. In organizations that require SSO, Account Service Keys are not accepted for managing the organization's SSO settings, deleting the organization, or checking whether it can be deleted.

Headers

Idempotency-Key
string
required

Identifies one logical mutation across retries.

Required string length: 1 - 255
Pattern: ^[\x21-\x7e]{1,255}$

Path Parameters

destinationId
string
required
Pattern: ^pho_whd_[0-7][0-9a-hjkmnp-tv-z]{25}$
projectId
string
required
Pattern: ^pho_prj_[0-7][0-9a-hjkmnp-tv-z]{25}$

Body

application/json
overlapSeconds
integer
default:86400
Required range: 0 <= x <= 604800

Response

The new signing secret.

previousSecretExpiresAt
string<date-time> | null
required
Pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
Example:

"2026-01-01T00:00:00.000Z"

signingSecret
string
required
Pattern: ^whsec_.*