Webhooks
Rotate your webhook signing secret
Replace the webhook signing secret. The old one keeps signing deliveries for 24 hours so you can switch over.
POST
Rotate your webhook signing secret
Rotate the secret if it may have leaked, or as routine hygiene. You get the new secret in the response.
For the next 24 hours every delivery is signed with both secrets, new first:
previous_valid_until in the response says when the old one stops. Update your receiver to the new secret before then. A receiver that splits the header on commas and accepts any match keeps working the whole time.
Rotating with an API key needs the webhooks:write scope. You can also rotate from Settings → API Keys in the app.Authorizations
API key with the vd_sk_ prefix. Create keys from Settings, API Keys in the dashboard.
Response
The new signing secret.
Your signing secret. Keep it private.
Example:
"X-Valendata-Signature"
Example:
"HMAC-SHA256 over '<timestamp>.<raw body>'"
Set for 24 hours after a rotation: until then deliveries are also signed with the previous secret.
When the secret was last rotated.

