> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hyperprop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate signing secret

> Generates a new HMAC-SHA256 signing secret for this webhook. The old secret is invalidated **immediately** — update your verification code before rotating.

The new secret is returned in this response **only**. Save it.


**Authentication:** send your organization API key in the `X-API-Key` header.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/organization/webhooks/{webhookId}/rotate-secret
openapi: 3.0.0
info:
  title: Hyperprop Platform API
  version: 1.0.0
  description: >-
    REST API for the Hyperprop Trading Platform — provision evaluation and
    funded trading accounts, manage traders and plans, react to account
    lifecycle events via signed webhooks, and reconcile billing. Built for prop
    firms integrating from their own backend.


    Authentication, quick start, error handling, idempotency, pagination, custom
    metadata, webhooks, and the MCP connector are documented at
    https://docs.hyperprop.com.
  x-logo:
    url: https://app.hyperprop.com/logo-icon.svg
    altText: Hyperprop
    href: https://hyperprop.com
servers:
  - url: https://api.hyperprop.com/platform
    description: Production
security: []
tags:
  - name: Trading accounts
    description: Create, update, and inspect trading accounts.
  - name: Traders
    description: Look up and update the traders in your organization.
  - name: Trading plans
    description: Define the plans you sell.
  - name: Trading rules
    description: Define how accounts are evaluated.
  - name: Lockouts
    description: Pause and resume trading on an account.
  - name: Payouts
    description: Check payout eligibility and record payouts.
  - name: Purchases
    description: Purchases recorded for your organization.
  - name: Time Machine
    description: Restore accounts to an earlier trading day or instant.
  - name: Webhooks
    description: Register webhook endpoints and inspect deliveries.
  - name: Events
    description: Your organization's event history and real-time event stream.
  - name: Reconciliation
    description: Balances, end-of-day snapshots, and fills for reconciliation.
  - name: Analytics
    description: Organization performance and plan economics.
  - name: Billing
    description: 'Your Hyperprop bill: activity, billing cycles, and forecasts.'
  - name: Team and roles
    description: Manage dashboard access for your staff.
  - name: API keys
    description: Manage your organization's API key.
  - name: Logs and health
    description: API request logs, the audit log, and integration health.
  - name: Organization profile
    description: Your organization's profile and logo.
  - name: Support
    description: Open and follow up on support tickets.
  - name: Partner access
    description: >-
      Read a trader's journal as an approved partner app, with the trader's own
      key.
paths:
  /v1/organization/webhooks/{webhookId}/rotate-secret:
    post:
      tags:
        - Webhooks
      summary: Rotate signing secret
      description: >-
        Generates a new HMAC-SHA256 signing secret for this webhook. The old
        secret is invalidated **immediately** — update your verification code
        before rotating.


        The new secret is returned in this response **only**. Save it.



        **Authentication:** send your organization API key in the `X-API-Key`
        header.
      operationId: postV1OrganizationWebhooksWebhookidRotatesecret
      parameters:
        - description: Webhook ID
          x-format:
            guid: true
          name: webhookId
          in: path
          required: true
          schema:
            type: string
      responses:
        '200':
          description: Secret rotated — new secret included in this response only
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model762'
        '401':
          description: Authentication required
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model9'
        '403':
          description: Access denied
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model47'
        '404':
          description: Webhook not found
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model368'
        '500':
          description: An unexpected error occurred
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model5'
      security:
        - X-API-Key: []
components:
  schemas:
    Model762:
      type: object
      properties:
        success:
          type: boolean
          example: true
        data:
          $ref: '#/components/schemas/Model761'
        message:
          type: string
          example: >-
            Secret rotated. Save your new signing secret — it won't be shown
            again.
    Model9:
      type: object
      properties:
        success:
          type: boolean
          description: Always false on errors
          example: false
        statusCode:
          type: number
          example: 401
        error:
          type: string
          example: Unauthorized
        message:
          type: string
          example: Authentication required
        code:
          type: string
          description: Machine-readable error code — switch on this, not on message text
          example: UNAUTHORIZED
    Model47:
      type: object
      properties:
        success:
          type: boolean
          description: Always false on errors
          example: false
        statusCode:
          type: number
          example: 403
        error:
          type: string
          example: Forbidden
        message:
          type: string
          example: Access denied
        code:
          type: string
          description: Machine-readable error code — switch on this, not on message text
          example: FORBIDDEN
    Model368:
      type: object
      properties:
        success:
          type: boolean
          description: Always false on errors
          example: false
        statusCode:
          type: number
          example: 404
        error:
          type: string
          example: Not Found
        message:
          type: string
          example: Webhook not found
        code:
          type: string
          description: Machine-readable error code — switch on this, not on message text
          example: NOT_FOUND
    Model5:
      type: object
      properties:
        success:
          type: boolean
          description: Always false on errors
          example: false
        statusCode:
          type: number
          example: 500
        error:
          type: string
          example: Internal Server Error
        message:
          type: string
          example: An unexpected error occurred
        code:
          type: string
          description: Machine-readable error code — switch on this, not on message text
          example: INTERNAL_ERROR
    Model761:
      type: object
      properties:
        id:
          type: string
          example: d2f3a1c0-8e7b-4f6a-9c5d-1234567890ab
          x-format:
            guid: true
        secret:
          type: string
          description: New signing secret. Save it — cannot be retrieved later.
          example: whsec_new_a1b2c3d4e5f6...
  securitySchemes:
    X-API-Key:
      type: apiKey
      name: X-API-Key
      in: header
      description: >-
        Organization API key. Format: "hp_live_{key}". Organization admins
        manage the key in the dashboard.

````

## Related topics

- [List all webhooks](/platform-api/webhooks/list-all-webhooks.md)
- [Update a webhook](/platform-api/webhooks/update-a-webhook.md)
- [Get webhook details](/platform-api/webhooks/get-webhook-details.md)
- [Redeliver a webhook delivery](/platform-api/webhooks/redeliver-a-webhook-delivery.md)
- [Quickstart](/quickstart.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.