Skip to main content
POST
Rotate a webhook's signing secret

Authorizations

Authorization
string
header
required

Personal API key, e.g. Authorization: Bearer sajn_sk_.... Not scope-limited — acts as the issuing user.

Headers

Sajn-Version
enum<string>

API version for this request. Without it, the request uses the organization's default version; an organization without a default is pinned to the latest version by its first request.

Available options:
2026-09,
2026-10
Idempotency-Key
string

Makes retries safe. A retry with the same key and the same request replays the stored response for 24 hours (header Idempotent-Replayed: true); the same key with a different request returns 400.

Maximum string length: 255

Path Parameters

id
string
required

The webhook ID.

Response

Webhook response

Webhook response

id
string
required

Unique webhook identifier

url
string
required

URL that receives webhook events

enabled
boolean
required

Whether this webhook is active

status
enum<string>
required

DISABLED when enabled is false. PAUSED when sajn stopped delivering because the endpoint failed for three days or answered 410 Gone; resume with POST /api/v1/webhooks/:id/reactivate.

Available options:
ENABLED,
DISABLED,
PAUSED
pausedAt
string<date-time> | null
required

When sajn paused the webhook. Null unless status is PAUSED.

pauseReason
string | null
required

Why sajn paused the webhook: HTTP_<status code> for the last answer, such as HTTP_410, or NETWORK_ERROR. Null unless status is PAUSED.

failureNotificationEmail
string | null
required

Email address that receives a notification if webhook delivery fails

events
enum<string>[]
required

The event types this webhook subscribes to

Available options:
document.created,
document.sent,
document.fully_signed,
document.completed,
document.rejected,
document.expired,
document.withdrawn,
document.updated,
document.deleted,
document.restored,
document.archived,
document.unarchived,
document.expiration_extended,
document.expiring_soon,
document.party.sent,
document.party.delivery_failed,
document.party.opened,
document.party.read,
document.party.signed,
document.party.rejected,
document.party.delegated,
document.party.auth_failed,
document.party.verified,
document.party.updated,
document.party.added,
document.party.removed,
document.party.reminded,
document.comment.created,
identity_check.created,
identity_check.sent,
identity_check.opened,
identity_check.verified,
identity_check.failed,
identity_check.cancelled,
contact.created,
contact.updated,
contact.deleted,
company.created,
company.updated,
company.deleted,
template.created,
template.updated,
template.deleted,
template.restored,
form.submitted,
workspace.created,
member.added,
member.invited,
member.invite_accepted,
approval_request.created,
approval_request.approved,
approval_request.rejected,
approval_request.cancelled,
login.completed,
login.failed,
security.document_downloaded,
security.documents_exported,
security.signature_identity_accessed,
security.member_removed,
security.member_role_changed,
security.role_updated,
security.workspace_retention_updated,
usage.limit_reached
apiVersion
string
required

API version, in YYYY-MM format, that determines the payload shape this endpoint receives

createdAt
string<date-time>
required

Date and time when webhook was created

updatedAt
string<date-time>
required

Date and time when webhook was last updated

secret
string

Signing secret for this endpoint, in the Standard Webhooks format whsec_<base64>. Returned only when you create the webhook and when you rotate the secret, so store it then.