# Rotate a subscription secret

`POST https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret`

Replace a webhook subscription's signing secret, with a grace period in which both sign.

## Path params

- `workspace_id` (string), required: Your workspace. A credential bound to a workspace may name only its own.
- `subscription_id` (string), required: The webhook subscription: `sub_` and 26 characters.

## Headers

- `Authorization` (string), required: Bearer <API key>
- `Content-Type` (string), required: application/json, on a call with a body

## Description

Takes no body. Answers `200` with the new `signing_secret`, shown once, and `previous_valid_until`: until then each delivery carries a signature for each secret, newest first. See the [Webhooks guide](/en/guides/webhooks/).

## Request

**cURL**

```sh
# The body is {} here: see parameters.
curl -X POST "https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret" \
  -H "Authorization: Bearer $INOVACC_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{}'
```

**TypeScript**

```ts
// The body is {} here: see parameters.
const body: Record<string, unknown> = {};

const url = "https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret";

const response = await fetch(url, {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.INOVACC_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify(body),
});

console.log(response.status, await response.text());
```

**Python**

```py
import json
import os
import urllib.request

# The body is {} here: see parameters.
body = {}

request = urllib.request.Request(
    "https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret",
    data=json.dumps(body).encode(),
    method="POST",
    headers={
        "User-Agent": "inovacc-python-sample",
        "Authorization": "Bearer " + os.environ["INOVACC_API_KEY"],
        "Content-Type": "application/json",
    },
)

with urllib.request.urlopen(request) as response:
    print(response.status, response.read().decode())
```

**Go**

```go
package main

import (
	"fmt"
	"io"
	"net/http"
	"os"
	"strings"
)

const url = "https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret"

// The body is {} here: see parameters.
const body = `{}`

func main() {
	req, err := http.NewRequest("POST", url, strings.NewReader(body))
	if err != nil {
		panic(err)
	}
	req.Header.Set("Authorization", "Bearer "+os.Getenv("INOVACC_API_KEY"))
	req.Header.Set("Content-Type", "application/json")

	res, err := http.DefaultClient.Do(req)
	if err != nil {
		panic(err)
	}
	defer res.Body.Close()

	out, err := io.ReadAll(res.Body)
	if err != nil {
		panic(err)
	}
	fmt.Println(res.Status, string(out))
}
```

**Rust**

```rs
// Cargo.toml: reqwest = { version = "0.12", features = ["blocking", "json"] }
// Cargo.toml: serde_json = "1"

fn main() -> Result<(), Box<dyn std::error::Error>> {
    let api_key = std::env::var("INOVACC_API_KEY")?;
    // The body is {} here: see parameters.
    let body = serde_json::json!({});
    let response = reqwest::blocking::Client::new()
        .post("https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret")
        .bearer_auth(api_key)
        .json(&body)
        .send()?;
    println!("{} {}", response.status(), response.text()?);
    Ok(())
}
```

**JavaScript**

```mjs
// The body is {} here: see parameters.
const body = {};

const url = "https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret";

const response = await fetch(url, {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.INOVACC_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify(body),
});

console.log(response.status, await response.text());
```

**PHP**

```php
<?php

// The body is {} here: see parameters.
$body = <<<'JSON'
{}
JSON;

$curl = curl_init('https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret');
curl_setopt_array($curl, [
    CURLOPT_CUSTOMREQUEST => 'POST',
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => [
        'Authorization: Bearer ' . getenv('INOVACC_API_KEY'),
        'Content-Type: application/json',
    ],
    CURLOPT_POSTFIELDS => $body,
]);

$response = curl_exec($curl);
echo curl_getinfo($curl, CURLINFO_HTTP_CODE), ' ', $response, "\n";
curl_close($curl);
```

**Ruby**

```rb
require "net/http"
require "uri"

uri = URI('https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret')
# The body is {} here: see parameters.
body = <<~'JSON'
{}
JSON

request = Net::HTTP::Post.new(uri)
request["Authorization"] = "Bearer #{ENV.fetch('INOVACC_API_KEY')}"
request["Content-Type"] = "application/json"
request.body = body

response = Net::HTTP.start(uri.host, uri.port, use_ssl: uri.scheme == "https") do |http|
  http.request(request)
end

puts "#{response.code} #{response.body}"
```

**Java**

```java
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

public class Main {
    public static void main(String[] args) throws Exception {
        String apiKey = System.getenv("INOVACC_API_KEY");
        // The body is {} here: see parameters.
        String body = "{}";

        HttpRequest request = HttpRequest.newBuilder()
                .uri(URI.create("https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret"))
                .header("Authorization", "Bearer " + apiKey)
                .header("Content-Type", "application/json")
                .method("POST", HttpRequest.BodyPublishers.ofString(body))
                .build();

        HttpResponse<String> response = HttpClient.newHttpClient()
                .send(request, HttpResponse.BodyHandlers.ofString());
        System.out.println(response.statusCode() + " " + response.body());
    }
}
```

**C#**

```cs
using System.Text;

// The body is {} here: see parameters.
var body = "{}";

var url = "https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret";
var apiKey = Environment.GetEnvironmentVariable("INOVACC_API_KEY");

using var client = new HttpClient();
using var request = new HttpRequestMessage(HttpMethod.Post, url);
request.Headers.Add("Authorization", $"Bearer {apiKey}");
request.Content = new StringContent(body, Encoding.UTF8, "application/json");

using var response = await client.SendAsync(request);
Console.WriteLine($"{(int)response.StatusCode} {await response.Content.ReadAsStringAsync()}");
```

**Kotlin**

```kt
import java.net.URI
import java.net.http.HttpClient
import java.net.http.HttpRequest
import java.net.http.HttpResponse

fun main() {
    val apiKey = System.getenv("INOVACC_API_KEY")
    // The body is {} here: see parameters.
    val body = "{}"

    val request = HttpRequest.newBuilder()
        .uri(URI.create("https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret"))
        .header("Authorization", "Bearer " + apiKey)
        .header("Content-Type", "application/json")
        .method("POST", HttpRequest.BodyPublishers.ofString(body))
        .build()

    val response = HttpClient.newHttpClient()
        .send(request, HttpResponse.BodyHandlers.ofString())
    println("${response.statusCode()} ${response.body()}")
}
```

**Swift**

```swift
import Foundation
#if canImport(FoundationNetworking)
import FoundationNetworking
#endif

// The body is {} here: see parameters.
let body = #"""
{}
"""#

let apiKey = ProcessInfo.processInfo.environment["INOVACC_API_KEY"] ?? ""

let url = URL(string: "https://events.inovacc.dev/v1/workspaces/{workspace_id}/subscriptions/{subscription_id}/rotate-secret")!
var request = URLRequest(url: url)
request.httpMethod = "POST"
request.setValue("Bearer \(apiKey)", forHTTPHeaderField: "Authorization")
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.httpBody = Data(body.utf8)

let (data, response) = try await URLSession.shared.data(for: request)
let status = (response as? HTTPURLResponse)?.statusCode ?? 0
print(status, String(decoding: data, as: UTF8.self))
```

## Response

**200**

```json
{
  "subscription_id": "sub_01JCA4X9QY7M2KZ3N8PB5RT6VW",
  "signing_secret": "whsec_<shown once>",
  "previous_valid_until": "2026-10-07T12:00:00.000Z"
}
```

**401**: invalid_credentials

**403**: forbidden

**404**: subscription_not_found

**409**: wrong_delivery_mode, secret_not_managed

**429**: rate_limited

**503**: service_unavailable, signing_unavailable

## See also

- [Authentication](https://developer.inovacc.dev/en/guides/authentication/)
- [Errors](https://developer.inovacc.dev/en/guides/errors/)
- [Limits](https://developer.inovacc.dev/en/guides/limits/)
