> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nlbs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate webhook secret

> Rotate the signing secret. The new plaintext secret is returned only once.



## OpenAPI

````yaml https://api.qa.nlbs.ai/api/openapi.json post /webhooks/endpoints/{endpoint_uuid}/rotate-secret
openapi: 3.1.0
info:
  description: >-
    NL Labs AI AML API. Use Bearer API keys for protected endpoints. The /live
    and /ready probes are public.
  title: NL Labs AI
  version: 0.1.0
servers:
  - url: https://api.qa.nlbs.ai/api
security:
  - ApiKeyAuth: []
tags:
  - description: Runtime health checks and source freshness endpoints.
    name: health
  - description: Canonical entity lookup endpoints used before starting analyses.
    name: entities
  - description: AML analysis creation, status, result, and debug endpoints.
    name: analyses
  - description: Regulatory report (Motor 2) creation, status, result, and debug endpoints.
    name: reports
  - description: Versioned deterministic rules catalog endpoints.
    name: rules
  - description: Versioned regulatory reference catalog endpoints.
    name: regulatory
  - description: Webhook endpoint configuration and delivery-event operations.
    name: webhooks
paths:
  /webhooks/endpoints/{endpoint_uuid}/rotate-secret:
    post:
      tags:
        - webhooks
      summary: Rotate webhook secret
      description: >-
        Rotate the signing secret. The new plaintext secret is returned only
        once.
      operationId: rotate_webhook_secret
      parameters:
        - description: Webhook endpoint UUID.
          in: path
          name: endpoint_uuid
          required: true
          schema:
            description: Webhook endpoint UUID.
            format: uuid
            title: Endpoint Uuid
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebhookSecretRotateResponse'
          description: Successful Response
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Missing, malformed, expired, or invalid Bearer API key.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: The authenticated API key does not have the required scope.
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Webhook endpoint was not found for the authenticated client.
        '422':
          description: >-
            Invalid request body, path parameter, query parameter, or business
            rule.
      security:
        - HTTPBearer: []
components:
  schemas:
    WebhookSecretRotateResponse:
      description: >-
        Returned ONCE at secret rotation — new plaintext secret. Never returned
        again.
      properties:
        secret:
          description: New plaintext signing secret returned only once.
          title: Secret
          type: string
        uuid:
          description: Webhook endpoint UUID.
          format: uuid
          title: Uuid
          type: string
      required:
        - uuid
        - secret
      title: WebhookSecretRotateResponse
      type: object
    ErrorResponse:
      properties:
        detail:
          description: Stable public error message.
          examples:
            - Resource not found.
          title: Detail
          type: string
      required:
        - detail
      title: ErrorResponse
      type: object
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key

````