Skip to main content
POST
Rotate your webhook signing secret
Rotate the secret if it may have leaked, or as routine hygiene. You get the new secret in the response. For the next 24 hours every delivery is signed with both secrets, new first:
previous_valid_until in the response says when the old one stops. Update your receiver to the new secret before then. A receiver that splits the header on commas and accepts any match keeps working the whole time. Rotating with an API key needs the webhooks:write scope. You can also rotate from Settings → API Keys in the app.

Authorizations

Authorization
string
header
required

API key with the vd_sk_ prefix. Create keys from Settings, API Keys in the dashboard.

Response

The new signing secret.

secret
string

Your signing secret. Keep it private.

signature_header
string
Example:

"X-Valendata-Signature"

algorithm
string
Example:

"HMAC-SHA256 over '<timestamp>.<raw body>'"

previous_valid_until
string<date-time> | null

Set for 24 hours after a rotation: until then deliveries are also signed with the previous secret.

rotated_at
string<date-time> | null

When the secret was last rotated.