Skip to main content

Regenerate Webhook Secret

The Regenerate Webhook Secret endpoint issues a new HMAC secret for your signature webhook and immediately replaces the old one. Use the returned secret to verify the X-TurboDocx-Signature header on incoming webhook calls.

When to use it​

Use this endpoint if the current secret may have leaked, or as part of a routine credential rotation. Because the change takes effect immediately, update your webhook receiver's stored secret before or right after calling this endpoint; deliveries signed with the old secret will fail verification on your side as soon as it rotates.

Example request​

curl -X POST "https://api.turbodocx.com/api/webhooks/signature/regenerate" \
-H "Authorization: Bearer $TURBODOCX_API_KEY" \
-H "x-rapiddocx-org-id: $TURBODOCX_ORG_ID" \
-H "Accept: application/json"

Example response​

{
"data": {
"id": "b7e2c4a1-3f9d-4e6a-8c1b-5d0f7a2e9c34",
"secret": "whsec_REPLACE_WITH_YOUR_WEBHOOK_SECRET",
"regeneratedAt": "2026-05-02T09:20:00.000Z"
},
"message": "Webhook secret regenerated successfully. Save the new secret - it won't be shown again."
}

The full secret is only returned here and on Create Webhook; Get Webhook only ever returns a masked maskedSecret.

Common errors​

StatusWhenResponse body
401Missing or invalid API key/token, or the organization cannot be resolvedEmpty (status only)
403The key's role is not administratorEmpty (status only)
404No webhook with that name exists in your organization{ "error": "Webhook not found" }
  • Get Webhook to confirm the secret was rotated (maskedSecret changes)

  • Update Webhook to change URLs or events without rotating the secret

  • Test Webhook to confirm your receiver validates the new secret correctly