Rotate a webhook's signing secret
Generates a new signing secret and returns the webhook with it in secret. Store it: no other response returns it.
For 24 hours, every delivery carries two signatures in webhook-signature, one per secret, so you can deploy the new secret without dropping deliveries. A Standard Webhooks library accepts a request when any signature matches. After 24 hours, only the new secret signs.
Plan Requirement: Requires the Team plan or higher, or a sandbox organization.
Authorizations
Personal API key, e.g. Authorization: Bearer sajn_sk_.... Not scope-limited — acts as the issuing user.
Headers
API version for this request. Without it, the request uses the organization's default version; an organization without a default is pinned to the latest version by its first request.
2026-09, 2026-10 Makes retries safe. A retry with the same key and the same request replays the stored response for 24 hours (header Idempotent-Replayed: true); the same key with a different request returns 400.
255Path Parameters
The webhook ID.
Response
Webhook response
Webhook response
Unique webhook identifier
URL that receives webhook events
Whether this webhook is active
DISABLED when enabled is false. PAUSED when sajn stopped delivering because the endpoint failed for three days or answered 410 Gone; resume with POST /api/v1/webhooks/:id/reactivate.
ENABLED, DISABLED, PAUSED When sajn paused the webhook. Null unless status is PAUSED.
Why sajn paused the webhook: HTTP_<status code> for the last answer, such as HTTP_410, or NETWORK_ERROR. Null unless status is PAUSED.
Email address that receives a notification if webhook delivery fails
The event types this webhook subscribes to
document.created, document.sent, document.fully_signed, document.completed, document.rejected, document.expired, document.withdrawn, document.updated, document.deleted, document.restored, document.archived, document.unarchived, document.expiration_extended, document.expiring_soon, document.party.sent, document.party.delivery_failed, document.party.opened, document.party.read, document.party.signed, document.party.rejected, document.party.delegated, document.party.auth_failed, document.party.verified, document.party.updated, document.party.added, document.party.removed, document.party.reminded, document.comment.created, identity_check.created, identity_check.sent, identity_check.opened, identity_check.verified, identity_check.failed, identity_check.cancelled, contact.created, contact.updated, contact.deleted, company.created, company.updated, company.deleted, template.created, template.updated, template.deleted, template.restored, form.submitted, workspace.created, member.added, member.invited, member.invite_accepted, approval_request.created, approval_request.approved, approval_request.rejected, approval_request.cancelled, login.completed, login.failed, security.document_downloaded, security.documents_exported, security.signature_identity_accessed, security.member_removed, security.member_role_changed, security.role_updated, security.workspace_retention_updated, usage.limit_reached API version, in YYYY-MM format, that determines the payload shape this endpoint receives
Date and time when webhook was created
Date and time when webhook was last updated
Signing secret for this endpoint, in the Standard Webhooks format whsec_<base64>. Returned only when you create the webhook and when you rotate the secret, so store it then.

