WellMarked Docs
API referenceWebhooks

Mint a new webhook signing secret

Generate a new signing secret for webhook deliveries on the authenticated account. Every webhook this API sends is signed with this secret so your receiver can verify the payload actually came from us. Rotating takes effect immediately — deliveries in flight are signed with the old secret, so accept both for a short window when rotating a live receiver. The secret is returned **once, in this response**. Unmetered.

POST
/webhook/rotate

Authorization

BearerAuth
AuthorizationBearer <token>

Your API key, sent as Authorization: Bearer wm_.... Keys are wm_ followed by 40 hex characters. Create one with POST /register (free, no auth) or POST /keys.

In: header

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/webhook/rotate"
{  "rotated_at": "2019-08-24T14:15:22Z",  "webhook_signing_secret": "string"}