Skip to main content
import { createClient } from "@mailsai/sdk";

const client = createClient(); // reads MAILS_API_KEY

const result = await client.webhooks.rotateSecret(
  "whe_01JZX8K3M9Q4P7VN2YB6RTDC0E",
);
console.log(result);
{
  "id": "whe_01JZX8K3M9Q4P7VN2YB6RTDC0E",
  "signing_secret": "<signing_secret>",
  "secret_rotated_at": "2026-10-04T12:00:00.000Z",
  "previous_secret_expires_at": "2026-10-04T12:00:00.000Z"
}

Rotate the signing secret

Issues a new signing secret, returned once.
POST/v1/webhooks/{id}/rotate-secretscope · manage
import { createClient } from "@mailsai/sdk";

const client = createClient(); // reads MAILS_API_KEY

const result = await client.webhooks.rotateSecret(
  "whe_01JZX8K3M9Q4P7VN2YB6RTDC0E",
);
console.log(result);
{
  "id": "whe_01JZX8K3M9Q4P7VN2YB6RTDC0E",
  "signing_secret": "<signing_secret>",
  "secret_rotated_at": "2026-10-04T12:00:00.000Z",
  "previous_secret_expires_at": "2026-10-04T12:00:00.000Z"
}

Path Parameters

idstringrequired

Webhook endpoint id.

For the next 24 hours every delivery's X-Mails-Signature carries a v1 signature from the new secret and one from the previous secret, so a receiver can switch over without failing a delivery. Verify by accepting the header when any v1 matches. Rotating again within the 24 hours retires the oldest secret. Closed to apps connected by sign-in (403 connected_app_not_allowed), and to a key tied to one agent (403): use an API key not tied to an agent, or the mails CLI. If the mails CLI sign-in that rotated it (or made the key that did) is later ended because one of its refresh tokens was used twice, the secret is rotated again and the replaced one stops signing at once.

Response

idstring

Id of the endpoint whose secret was rotated (whe_…): the id in the path.

signing_secretstring

The new HMAC signing secret. SHOWN ONCE.

secret_rotated_atstring

When this rotation happened; the endpoint's own secret_rotated_at now shows the same time.

previous_secret_expires_atstring

Until this time every delivery carries a signature from the previous secret as well, so receivers can switch over without dropping events.

Was this page helpful?