> ## Documentation Index
> Fetch the complete documentation index at: https://nevermined.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate a webhook signing secret

> Generates a new HMAC signing secret for the subscription and immediately invalidates the previous one. Signatures computed with the old secret stop verifying as soon as this returns. The new plaintext secret is returned ONCE in the response and is never retrievable again. Requires a Nevermined API key. Requires organization admin privileges. Requires the organization to be on the Premium tier or higher.



## OpenAPI

````yaml /api-reference/organizations-openapi.json post /organizations/{orgId}/webhooks/{id}/rotate-secret
openapi: 3.0.0
info:
  title: Nevermined Organizations API
  description: >-
    Manage a Nevermined organization programmatically — members, tiers, groups &
    budgets, treasury wallets, customers, webhooks, analytics, and
    agent-discovery surfaces.
  version: 1.0.0
  contact: {}
servers:
  - url: https://api.sandbox.nevermined.app/api/v1
    description: Sandbox
  - url: https://api.live.nevermined.app/api/v1
    description: Live
security: []
tags:
  - name: Organizations
    x-group: General
    description: Organization settings, members & roles, and workspace context.
  - name: Organizations - Billing
    x-group: Billing
    description: Tiers, subscriptions, invoices, checkout, and the public tier catalog.
  - name: Groups
    x-group: Groups & Budgets
    description: Organization groups, per-group budgets, and shared payment methods.
  - name: Organizations - Wallets
    x-group: Wallets
    description: Custodial stablecoin treasury wallets.
  - name: Organizations - Customers
    x-group: Customers
    description: The white-label customer CRM (Enterprise).
  - name: Organizations - Analytics
    x-group: Analytics
    description: Revenue, MRR, usage, conversion, and per-member metrics.
  - name: Organizations - Webhooks
    x-group: Webhooks
    description: Outbound webhook subscriptions and deliveries.
  - name: Organizations - Activity
    x-group: Activity
    description: The organization activity feed.
  - name: Organizations - Realtime
    x-group: Realtime
    description: Realtime WebSocket secret management (Enterprise).
  - name: Invitations
    x-group: Invitations
    description: Invite people to an organization.
  - name: Organizations - Integration
    x-group: Agent Discovery
    description: >-
      Public agent-discovery surfaces (llms.txt, agentic-instructions.md,
      ai-catalog.json).
paths:
  /organizations/{orgId}/webhooks/{id}/rotate-secret:
    post:
      tags:
        - Organizations - Webhooks
      summary: Rotate a webhook signing secret
      description: >-
        Generates a new HMAC signing secret for the subscription and immediately
        invalidates the previous one. Signatures computed with the old secret
        stop verifying as soon as this returns. The new plaintext secret is
        returned ONCE in the response and is never retrievable again. Requires a
        Nevermined API key. Requires organization admin privileges. Requires the
        organization to be on the Premium tier or higher.
      operationId: WebhookSubscriptionsController_rotateSecret
      parameters:
        - name: orgId
          required: true
          in: path
          description: Organization ID
          schema:
            type: string
            example: org-abc123
        - name: id
          required: true
          in: path
          description: Webhook subscription ID
          schema:
            example: whs-9c2f1a7e
            type: string
      responses:
        '200':
          description: >-
            New plaintext secret returned once; the old secret is immediately
            invalidated
        '401':
          description: Missing or invalid Nevermined API key
        '403':
          description: >-
            Caller is not an organization admin, or the org is not on the
            Premium tier or higher
        '404':
          description: Subscription not found in this organization
      security:
        - Authorization: []
components:
  securitySchemes:
    Authorization:
      scheme: bearer
      bearerFormat: JWT
      type: http

````

## Related topics

- [List webhook subscriptions](/docs/api-reference/organizations--webhooks/list-webhook-subscriptions.md)
- [Get a webhook subscription](/docs/api-reference/organizations--webhooks/get-a-webhook-subscription.md)
- [Create a webhook subscription](/docs/api-reference/organizations--webhooks/create-a-webhook-subscription.md)
- [Update a webhook subscription](/docs/api-reference/organizations--webhooks/update-a-webhook-subscription.md)
- [Rotate a WebSocket secret](/docs/api-reference/organizations--realtime/rotate-a-websocket-secret.md)
