Rotate webhook signing secret
Generates a new per-endpoint signing secret (whsec_*) for the webhook
endpoint. The previous secret is invalidated immediately — any
deliveries signed before the rotation will fail signature verification
if they are retried after this point.
The new secret is returned only in this response. Verifa does not
store the plaintext, so capture and store it securely.
Authentication
Organization API key. Keys are prefixed with vk_live_ (production) or
vk_sandbox_ (sandbox).
Path parameters
Headers
API version date string (e.g. 2026-02-01). If omitted, the version
pinned to your API key is used.
Response
Secret rotated. The new secret is included in the response.
Per-endpoint HMAC-SHA256 signing secret. Used to verify the
X-Verifa-Signature header on outbound webhook deliveries
(HMAC over f"{t}.{raw_body}"). Always begins with whsec_.
Only returned at endpoint creation and secret rotation —
Verifa does not store the plaintext secret after this
response, so capture and store it securely.