Regenerate Webhook Secret
curl --request POST \
--url https://api.fyatu.com/api/v3/webhooks/secret/regenerate \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.fyatu.com/api/v3/webhooks/secret/regenerate"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.fyatu.com/api/v3/webhooks/secret/regenerate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.fyatu.com/api/v3/webhooks/secret/regenerate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.fyatu.com/api/v3/webhooks/secret/regenerate"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.fyatu.com/api/v3/webhooks/secret/regenerate")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.fyatu.com/api/v3/webhooks/secret/regenerate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"success": true,
"status": 200,
"message": "Webhook secret regenerated successfully",
"data": {
"webhookSecret": "whsec_x1y2z3a4b5c6d7e8f9g0h1i2j3k4l5m6",
"regeneratedAt": "2026-01-15T10:30:00+00:00",
"note": "Update your server with this new secret. The old secret is now invalid."
},
"meta": {
"requestId": "req_abc123xyz789",
"timestamp": "2026-01-15T10:30:00+00:00"
}
}
Configuration
Regenerate Webhook Secret
Generate a new HMAC-SHA256 webhook signing secret. Previous secret is immediately invalidated. POST /webhooks/regenerate-secret.
POST
/
webhooks
/
secret
/
regenerate
Regenerate Webhook Secret
curl --request POST \
--url https://api.fyatu.com/api/v3/webhooks/secret/regenerate \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.fyatu.com/api/v3/webhooks/secret/regenerate"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.fyatu.com/api/v3/webhooks/secret/regenerate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.fyatu.com/api/v3/webhooks/secret/regenerate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.fyatu.com/api/v3/webhooks/secret/regenerate"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.fyatu.com/api/v3/webhooks/secret/regenerate")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.fyatu.com/api/v3/webhooks/secret/regenerate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"success": true,
"status": 200,
"message": "Webhook secret regenerated successfully",
"data": {
"webhookSecret": "whsec_x1y2z3a4b5c6d7e8f9g0h1i2j3k4l5m6",
"regeneratedAt": "2026-01-15T10:30:00+00:00",
"note": "Update your server with this new secret. The old secret is now invalid."
},
"meta": {
"requestId": "req_abc123xyz789",
"timestamp": "2026-01-15T10:30:00+00:00"
}
}
Regenerate Webhook Secret
Generate a new webhook secret for signing webhook payloads. This immediately invalidates your previous secret.After regenerating your secret, you must update your webhook handler with the new secret. Any webhooks sent after regeneration will be signed with the new secret, and verification using the old secret will fail.
Request
curl -X POST https://api.fyatu.com/api/v3/webhooks/secret/regenerate \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"
Response
boolean
Whether the request was successful
object
{
"success": true,
"status": 200,
"message": "Webhook secret regenerated successfully",
"data": {
"webhookSecret": "whsec_x1y2z3a4b5c6d7e8f9g0h1i2j3k4l5m6",
"regeneratedAt": "2026-01-15T10:30:00+00:00",
"note": "Update your server with this new secret. The old secret is now invalid."
},
"meta": {
"requestId": "req_abc123xyz789",
"timestamp": "2026-01-15T10:30:00+00:00"
}
}
When to Regenerate
You should regenerate your webhook secret if:- Your secret was accidentally exposed
- An employee with access to the secret has left your organization
- You want to rotate secrets as a security best practice
- You suspect unauthorized access to your webhooks
After Regenerating
- Copy the new secret from the response immediately
- Update your webhook handler with the new secret
- Test webhook delivery using the Test Webhook endpoint
- Monitor your logs to ensure webhooks are being verified correctly
The old secret is invalidated immediately. There is no grace period. Make sure you’re ready to update your handler before regenerating.

