Webhooks
POST/v1/webhooks/endpoints/{id}/rotate-secret
Issue a new signing secret without losing an event
For 24 hours afterwards every delivery carries TWO v1 signatures — the new secret and the old one — so you can deploy the new value without the deliveries in between failing your check. Accept the delivery if any v1 matches; the SDK already does.
- Auth
- API key
- Scope
- webhooks:manage
- Rate limit
- DEFAULT
- Search quota
- Free
- Idempotency
- Idempotency-Key
Path parameters
Request headers
Request body
RotateWebhookSecretDto — required, sent as application/json.
Responses
Errors
Every one of these carries the same envelope. What each error.type means, and whether a retry can succeed, is on the error index — once, for all operations.
Response headers
Set on every response of this operation, successful or not.
Example
curl -sS -X POST "$VACABEE_API_URL/v1/webhooks/endpoints/<id>/rotate-secret" \
-H "Authorization: Bearer $VACABEE_API_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{}'The body above is empty because this operation declares no required fields — not because it takes none. Every field it accepts is optional, and they are listed under RotateWebhookSecretDto in the schema catalogue.
Set VACABEE_API_URL to https://api.vacabee.com with a live key, or to https://sandbox-api.vacabee.com with a vcb_test_ key. Binding a host to one kind of key is planned and is not enforced by the host yet, so nothing stops a key from being answered at the wrong base URL — assert the prefix against your configured URL yourself. What the sandbox answers
TypeScript SDK
await vacabee.webhooks.rotateSecret(…);The typed method sends the right headers, derives the idempotency key where one is required, and returns the response type generated from this document. Installing and using the SDK

