Meet the new Scripe, live on October 7.Register

OpenAPI reference · Webhooks

Rotate the endpoint's signing secret

POST/webhook-endpoints/{endpointId}/rotate-secret

Mint a new plaintext signing secret and persist it as the canonical secret for the endpoint. The response carries the plaintext once; future reads expose only secretLast4.

In-flight deliveries finish signing with the previous secret; anything enqueued after the rotation lands uses the new one. Plan a brief overlap window in your receiver if you can't afford a single missed verification.

Not idempotent — every call generates a fresh secret. Requires the webhooks:manage scope.

Authorization

  • Authorizationstringrequired

    Bearer token in the Authorization header.

    Pass Authorization: Bearer scripe_sk_live_<...> (or scripe_sk_test_<...> for test keys) on every request. Keys are scoped to a single workspace and can be revoked from the Scripe dashboard.

    The same header also accepts an OAuth 2.1 access token (scripe_oat_*); both credentials share one scope vocabulary and every operation below documents the scope it requires. An API key can hold every scope named on this surface except webhooks:manage, which is grantable to OAuth tokens only today — the webhook-endpoint operations answer 403 scope_missing to every API key. Operations that name no scope accept any valid token of the workspace.

Path parameters

  • endpointIdstringrequired

Header parameters

  • Scripe-Api-Versionstring

    Pin the API version. Format YYYY-MM-DD. Omit to receive the currently rolling default. Unknown versions return 400 version_unsupported.

Responses

  • 200

    Secret rotated. Response carries the new plaintext secret.

  • 401

    Missing, malformed, expired, or revoked API key.

  • 403

    Plan not eligible, scope missing, or workspace mismatch.

  • 404

    Resource not found in this workspace.

  • 429

    Sliding-window rate limit exceeded.

Example request

bash
curl --request POST \
  --url 'https://api.scripe.io/v1/webhook-endpoints/{endpointId}/rotate-secret' \
  --header 'Authorization: Bearer <token>'

Example response (200)

json
{
  "data": {
    "id": "whe_a1b2c3d4e5f6g7h8",
    "url": "https://hooks.example.com/scripe",
    "name": "Production CRM",
    "events": [
      "post.created",
      "job.completed"
    ],
    "isActive": true,
    "disabledReason": "string",
    "projectId": "string",
    "secretLast4": "string",
    "createdAt": "2026-08-10T09:00:00Z",
    "updatedAt": "2026-08-10T09:00:00Z",
    "secret": "whsec_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
  }
}