Rotate the signing secret
POST
https://fomodata.dev /v1 /webhooks /{id} /rotate-secretIssues a new whsec_… secret, returned once. It takes effect immediately; the previous secret stops signing.
Example request
curl -X POST 'https://fomodata.dev/v1/webhooks/wh_8Tq3NkVz1LmB5xRc7pYd2F/rotate-secret' \
-H "Authorization: Bearer $FOMODATA_API_KEY"Parameters
Path parameters
idstringrequired- e.g.
wh_8Tq3NkVz1LmB5xRc7pYd2F
Response
200 The webhook with its new secret (shown once)
application/jsonWebhookWithSecret
objectenumrequired"webhook"idstringrequiredurlstring (uri)requireddescriptionstring | nullrequiredeventsarray<EventType>requiredfiltersobjectrequired+ 3 child attributestokenarray<string>Token refs ($SYMBOL, address or tk_ id).handlearray<string>chainarray<string>
statusenumrequired"enabled""disabled""disabled_failing"secret_prefixstringrequiredlivemodebooleanrequiredcreated_atstring (date-time)requiredupdated_atstring (date-time)requiredsecretstringrequiredSigning secret — shown ONLY in the create/rotate response.
200 · exampleJSON
{
"object": "webhook",
"id": "wh_8Tq3NkVz1LmB5xRc7pYd2F",
"url": "https://example.com",
"description": "string",
"events": [
"thesis.created"
],
"filters": {
"token": [
"string"
],
"handle": [
"string"
],
"chain": [
"string"
]
},
"status": "enabled",
"secret_prefix": "whsec_Ab12",
"livemode": true,
"created_at": "2026-10-07T10:04:12.000Z",
"updated_at": "2026-10-07T10:04:12.000Z",
"secret": "string"
}Errors
| Status | When |
|---|---|
401 | Missing, invalid, revoked or expired API key |
403 | Insufficient scope, live access not approved, or history limit |
404 | Not found (or feature disabled) |
429 | Rate limit or quota exceeded |
All errors use the standard envelope. See error codes for every code value.