> ## Documentation Index
> Fetch the complete documentation index at: https://docs.caratuva.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate the signing secret

> Generates a new HMAC signing secret for the subscription and invalidates the previous one immediately. The new `secret` is returned ONCE in this response and is never retrievable again — update your signature-verification config before the next delivery arrives.



## OpenAPI

````yaml https://api.caratuva.com/docs-json post /v1/webhooks/{id}/rotate-secret
openapi: 3.0.0
info:
  title: Caratuva API
  description: >-
    Cross-border B2B payments. Fiat on-ramp → USDC → PIX off-ramp.


    Every request runs in **test** or **live** mode on this single host — there
    is no separate sandbox URL. API keys carry the mode in their prefix
    (`pk_test_…` / `pk_live_…`); dashboard JWTs start in test and re-mint via
    `POST /v1/auth/switch-mode`. Test mode runs the full pipeline against a
    sandbox payment instance (KYB/KYC auto-approve, no real money); live runs on
    real rails and requires approved KYB. Test and live data are fully isolated.
    Check readiness with `GET /v1/onboarding/status`.
  version: 1.0.0
  contact: {}
servers: []
security: []
tags:
  - name: Invoices
    description: Create and manage invoices that collect for one of your sellers.
  - name: Payments
    description: Create a payment (keep your own checkout), fetch it, or cancel it.
  - name: Accounts
    description: >-
      Onboard and manage your sellers, buyers, and your own (self) account at
      the settlement partner.
  - name: Webhooks
    description: Subscribe to outbound event notifications and manage signing secrets.
  - name: API keys
    description: Issue, list, and revoke the API keys that authenticate your integration.
  - name: Access
    description: Request and check production (live-mode) access for your organization.
  - name: Reports
    description: Pull settlement and transfer-pricing reports.
paths:
  /v1/webhooks/{id}/rotate-secret:
    post:
      tags:
        - Webhooks
      summary: Rotate the signing secret
      description: >-
        Generates a new HMAC signing secret for the subscription and invalidates
        the previous one immediately. The new `secret` is returned ONCE in this
        response and is never retrievable again — update your
        signature-verification config before the next delivery arrives.
      operationId: WebhooksOutboundController_rotate
      parameters:
        - name: id
          required: true
          in: path
          schema:
            type: string
      responses:
        '200':
          description: >-
            Secret rotated — the new `secret` is surfaced ONCE; the old one is
            now invalid.
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  orgId:
                    type: string
                  url:
                    type: string
                  eventTypes:
                    type: array
                    items:
                      type: string
                  active:
                    type: boolean
                  createdAt:
                    type: string
                  updatedAt:
                    type: string
                  secret:
                    type: string
                required:
                  - id
                  - orgId
                  - url
                  - eventTypes
                  - active
                  - createdAt
                  - updatedAt
                  - secret
                additionalProperties: false
              examples:
                default:
                  value:
                    id: ckwh001
                    orgId: ckorg001
                    url: https://erp.example.com/webhooks/caratuva
                    eventTypes:
                      - payment_intent.settled
                      - payment_intent.failed
                    active: true
                    createdAt: '2026-06-30T12:00:00.000Z'
                    updatedAt: '2026-06-30T12:00:00.000Z'
                    secret: whsec_8d2b6f4a0c1e3b5d7f9a0c2e4f6a8c1e
        '404':
          description: NotFound — No webhook subscription with that id for your org.
          content:
            application/json:
              schema:
                type: object
                properties:
                  statusCode:
                    type: integer
                    example: 404
                  error:
                    type: string
                    example: NotFound
                  message:
                    type: string
                    example: No webhook subscription with that id for your org.
      security:
        - apiKey: []
        - bearer: []
components:
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: X-API-Key
    bearer:
      scheme: bearer
      bearerFormat: JWT
      type: http

````