Regenerate Webhook Secret
The Regenerate Webhook Secret endpoint issues a new HMAC secret for your signature webhook and immediately replaces the old one. Use the returned secret to verify the X-TurboDocx-Signature header on incoming webhook calls.
When to use it
Use this endpoint if the current secret may have leaked, or as part of a routine credential rotation. Because the change takes effect immediately, update your webhook receiver's stored secret before or right after calling this endpoint; deliveries signed with the old secret will fail verification on your side as soon as it rotates.
Example request
curl -X POST "https://api.turbodocx.com/api/webhooks/signature/regenerate" \
-H "Authorization: Bearer $TURBODOCX_API_KEY" \
-H "x-rapiddocx-org-id: $TURBODOCX_ORG_ID" \
-H "Accept: application/json"
Example response
{
"data": {
"id": "b7e2c4a1-3f9d-4e6a-8c1b-5d0f7a2e9c34",
"secret": "whsec_REPLACE_WITH_YOUR_WEBHOOK_SECRET",
"regeneratedAt": "2026-05-02T09:20:00.000Z"
},
"message": "Webhook secret regenerated successfully. Save the new secret - it won't be shown again."
}
The full secret is only returned here and on Create Webhook; Get Webhook only ever returns a masked maskedSecret.
Common errors
| Status | When | Response body |
|---|---|---|
| 401 | Missing or invalid API key/token, or the organization cannot be resolved | Empty (status only) |
| 403 | The key's role is not administrator | Empty (status only) |
| 404 | No webhook with that name exists in your organization | { "error": "Webhook not found" } |
Related endpoints
-
Get Webhook to confirm the secret was rotated (
maskedSecretchanges) -
Update Webhook to change URLs or events without rotating the secret
-
Test Webhook to confirm your receiver validates the new secret correctly
POST/api/webhooks/signature/regenerate