> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kemycard.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate Webhook Secret

> Generates a new HMAC secret for this endpoint. The old secret is **invalidated immediately**.
Update your server code with the new secret before any pending deliveries arrive.




## OpenAPI

````yaml POST /webhooks/{code}/rotate-secret
openapi: 3.1.0
info:
  title: KemyCard API
  version: '1.0'
  description: >
    KemyCard API allows you to issue virtual and physical cards, manage KYC/POA
    verification,

    create crypto wallets, virtual bank accounts, and purchase gift cards.
  contact:
    name: KemyCard API Support
    email: hi@kemycard.com
servers:
  - url: https://api.kemycard.com/v1
    description: Production
security:
  - BearerAuth: []
tags:
  - name: Customers
    description: Manage your customers
  - name: Card Products
    description: Browse the card product catalog
  - name: Cards
    description: Issue and manage cards
  - name: KYC
    description: Identity verification
  - name: POA
    description: Proof of address verification
  - name: Wallets
    description: Crypto wallets
  - name: Virtual Accounts
    description: Virtual bank accounts
  - name: Gift Cards
    description: Gift card catalog and purchases
  - name: Balance
    description: Operational balances and transaction history
  - name: Webhooks
    description: Webhook endpoints and delivery management
paths:
  /webhooks/{code}/rotate-secret:
    post:
      tags:
        - Webhooks
      summary: Rotate webhook secret
      description: >
        Generates a new HMAC secret for this endpoint. The old secret is
        **invalidated immediately**.

        Update your server code with the new secret before any pending
        deliveries arrive.
      operationId: rotateWebhookSecret
      parameters:
        - name: code
          in: path
          required: true
          schema:
            type: string
            format: uuid
          description: Webhook endpoint UUID
      responses:
        '200':
          description: New secret generated
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    example: true
                  data:
                    type: object
                    properties:
                      code:
                        type: string
                        format: uuid
                      secret:
                        type: string
                        example: whsec_a1b2c3d4e5f6...
                      message:
                        type: string
                        example: >-
                          Secret rotated successfully. Update your webhook
                          verification code immediately.
        '404':
          $ref: '#/components/responses/NotFound'
components:
  responses:
    NotFound:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            success: false
            error:
              code: RESOURCE_NOT_FOUND
              message: Resource not found.
              details: null
  schemas:
    ErrorResponse:
      type: object
      properties:
        success:
          type: boolean
          example: false
        error:
          type: object
          properties:
            code:
              type: string
              example: VALIDATION_ERROR
            message:
              type: string
              example: Missing required fields.
            details:
              type: object
              nullable: true
        meta:
          $ref: '#/components/schemas/Meta'
    Meta:
      type: object
      properties:
        request_id:
          type: string
          example: a4f8e2c1b3d97056
        mode:
          type: string
          enum:
            - test
            - live
          example: test
        timestamp:
          type: string
          format: date-time
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: API key (sk_test_... or sk_live_...)

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.